Bar Haim is a security-focused Research and Development Engineer at IBM with nine years of backend and security engineering experience. Based in Sderot, Israel, he combines hands-on software development with security research to deliver scalable, auditable defense systems. An active open-source contributor, he advanced STIX translation for SigmaHQ/sigma (including x-sigma support) and enhanced STIX backends in stix-shifter for QRadar and Elastic ECS. His career spans IBM Innovation Center initiatives, along with roles as a SOC analyst and security researcher earlier in his trajectory. He holds a multidisciplinary academic background in physics, computer science, and communications engineering, complemented by an MBA from Ben-Gurion University, underscoring a blend of analytical rigor and business acumen.
This project consists of an open source library allowing software to connect to data repositories using STIX Patterning, and return results as STIX Observations.
Role in this project:
Back-end Developer & Security Engineer
Contributions:13 reviews, 14 commits, 21 PRs in 1 year 4 months
Contributions summary:Bar focused on improving the project's STIX translation capabilities, specifically for the QRadar and Elastic ECS modules. Their work involved bug fixes related to escaping values, handling the LIKE operator, and correctly translating IPv4/IPv6 addresses. Furthermore, they addressed missing features in the Elastic ECS query construction and added support for carbon black response events. The user also contributed to the project by adding and updating search fields for different ECS network fields.
Contributions:3 reviews, 19 commits, 8 PRs in 1 month
Contributions summary:Bar contributed to the development of a STIX (Structured Threat Information Expression) backend for the Sigma rule repository. This involved implementing custom STIX object support, specifically "x-sigma", to handle fields missing mappings. The user also modified the STIX backend to include support for keywords without field, and modified existing backend code to better handle AND/OR/NOT logic. This work enhanced the repository's ability to translate Sigma rules into STIX patterns for security analysis.
signaturessysmonrulesecurityids
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.