Thomas Patzke
|
3e2184ac61
|
Removal from sigma.backends.elasticsearch
|
2018-07-21 00:37:36 +02:00 |
|
Thomas Patzke
|
a9257c32c6
|
Sigma tools release 0.6
|
2018-07-17 23:12:23 +02:00 |
|
nikotin
|
b5f27d75be
|
Added Qradar backend
|
2018-07-17 15:25:06 +03:00 |
|
Thomas Patzke
|
c2b1a58813
|
Removal from sigma.backends.wdatp
|
2018-07-10 23:49:39 +02:00 |
|
Thomas Patzke
|
45782c6328
|
Removal from sigma.backends.splunk
|
2018-07-10 23:48:47 +02:00 |
|
Thomas Patzke
|
46f29d2eb2
|
Removal from sigma.backends.output
|
2018-07-10 23:47:41 +02:00 |
|
Thomas Patzke
|
2d4145cfe8
|
Removal from sigma.backends.discovery
|
2018-07-10 23:46:52 +02:00 |
|
Thomas Patzke
|
83acff6859
|
Splitting backends - Copy discovery.py
|
2018-07-10 23:46:16 +02:00 |
|
Thomas Patzke
|
d340487e94
|
Removal from sigma.backends.base
|
2018-07-10 23:44:14 +02:00 |
|
Thomas Patzke
|
2e7d366da5
|
Removal from sigma.backends.mixins
|
2018-07-10 23:42:38 +02:00 |
|
Thomas Patzke
|
bb78c1428e
|
Removal from sigma.backends.logpoint
|
2018-07-10 23:41:15 +02:00 |
|
Thomas Patzke
|
2edeaee748
|
Removal from sigma.backends.graylog
|
2018-07-10 23:40:17 +02:00 |
|
Thomas Patzke
|
e5baca0ac4
|
Removal from sigma.backends.qualys
|
2018-07-10 23:39:18 +02:00 |
|
Thomas Patzke
|
fdfe346adc
|
Removal from sigma.backends.exceptions
|
2018-07-10 23:37:59 +02:00 |
|
Thomas Patzke
|
7fbc3a35a3
|
Removal from sigma.backends.cli
|
2018-07-10 23:33:40 +02:00 |
|
Thomas Patzke
|
881f72e418
|
Removal from sigma.backends.tools
|
2018-07-10 23:32:42 +02:00 |
|
Thomas Patzke
|
09ac41949c
|
Removal from sigma.backends.archsight
|
2018-07-10 23:22:36 +02:00 |
|
Thomas Patzke
|
04b89befce
|
Splitting backends - Copy elasticsearch.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
bb9bef4deb
|
Splitting backends - Copy wdatp.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
72480d304b
|
Splitting backends - Copy splunk.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
c5d5c52850
|
Splitting backends - Copy output.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
0c93040da5
|
Splitting backends - Copy base.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
a8e19bb4ba
|
Splitting backends - Copy mixins.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
116fe16512
|
Splitting backends - Copy logpoint.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
b621e9c3a8
|
Splitting backends - Copy graylog.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
a2ee36eac7
|
Splitting backends - Copy qualys.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
32c70b26d8
|
Splitting backends - Copy exceptions.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
43d951b173
|
Splitting backends - Copy cli.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
a6cd7a3d6b
|
Splitting backends - Copy tools.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
7a2b1ae790
|
Splitting backends - Copy arcsight.py
|
2018-07-10 23:15:04 +02:00 |
|
Thomas Patzke
|
d064d24fbe
|
Sigmac WDATP backend: renamed action types
|
2018-07-10 22:49:38 +02:00 |
|
Thomas Patzke
|
0cdfc776de
|
Sigma tools release 0.5
|
2018-07-03 00:07:43 +02:00 |
|
Thomas Patzke
|
67158ba1d2
|
Merge branch 'master' of https://github.com/SaltyHash123/sigma into SaltyHash123-master
|
2018-07-02 23:14:04 +02:00 |
|
Florian Roth
|
2a74a62c67
|
Config file for SPARK scanner
|
2018-06-29 16:42:16 +02:00 |
|
Roey
|
14464f8c79
|
Added support of splunk dashboards (xml)
|
2018-06-22 14:17:58 +02:00 |
|
Thomas Patzke
|
7d1b801858
|
Merge branch 'devel-sigmac-wdatp'
|
2018-06-22 00:43:23 +02:00 |
|
Thomas Patzke
|
d8e036f737
|
sigmac: Parameter for ignoring "not supported" errors
Used to pass tests with complete rule set that would fail for backends
which target systems don't support required features.
|
2018-06-22 00:23:59 +02:00 |
|
Thomas Patzke
|
31727b3b25
|
Added Windows Defender ATP backend
Missing:
* Aggregations
|
2018-06-22 00:03:10 +02:00 |
|
Thomas Patzke
|
e72c0d5de4
|
SingleTextQueryBackend ignores empty components in composed queries
Example: one component of a AND-composition is ignored if invoked
generate* call returns None.
|
2018-06-21 23:59:41 +02:00 |
|
Thomas Patzke
|
d8a7bcad39
|
Reordered rule generation
Generation of query parts before and after main query gives access to
information possibly gathered while main query generation.
|
2018-06-21 23:50:13 +02:00 |
|
Florian Roth
|
3d52030391
|
Changed help text for -r flag
|
2018-06-13 00:08:46 +02:00 |
|
Florian Roth
|
7edd95744a
|
Windows NTLM
|
2018-06-13 00:08:46 +02:00 |
|
Florian Roth
|
c9658074dd
|
Removed "not yet implemented" comment from -r flag
|
2018-06-13 00:08:46 +02:00 |
|
Thomas Patzke
|
f6d5e5dd99
|
Sigmac parameter -I now ignores all backend errors
New backends introduced further exceptions and the intention of -I is to
get a successful run.
|
2018-06-07 23:33:12 +02:00 |
|
Thomas Patzke
|
8ddb369df3
|
Integration of Qualys backend
* Changed description text to one-liner
* Output to intended class
* Minor code optimizations
|
2018-06-07 23:31:09 +02:00 |
|
Thomas Patzke
|
ce9db548ff
|
Integration of ArcSight backend
* Rename
* Changed description to one line to beautify output of backend list
* Small bugfix in handling of numeric values
|
2018-06-07 23:04:36 +02:00 |
|
nikotin
|
d13e8d7bd3
|
Added ArcSight & Qualys backends
|
2018-06-07 16:18:23 +03:00 |
|
Florian Roth
|
4eabc5ea5c
|
Sigmac Usage
|
2018-06-01 10:33:11 +02:00 |
|
Florian Roth
|
65cc78f9e8
|
Windows Config Update - DNS logs
|
2018-05-22 16:59:58 +02:00 |
|
Paul Dutot
|
715a88542d
|
Graylog backend added
|
2018-05-17 15:51:25 +01:00 |
|