Tim Shelton
df315f5e08
enforcing snake case per hawk-analyticsd specs
2021-12-01 15:51:22 +00:00
Tim Shelton
caf47a9e3d
reducing score minus 5 for lows... will need a multitude
2021-12-01 14:33:28 +00:00
Tim Shelton
6927b0e69f
Fixing added backslashes that are generated by sigma backend
2021-12-01 13:29:15 +00:00
Julien Doutre
3fc0d80280
Fix config init
2021-11-29 18:08:34 +01:00
Julien Doutre
b2645eb017
Handle facets and attributes
2021-11-29 17:23:23 +01:00
Julien Doutre
230705d28c
Support null values
2021-11-29 16:13:23 +01:00
Julien Doutre
b114c76afe
Consistent regexp
2021-11-29 15:20:05 +01:00
Julien Doutre
beab887ad1
Escape queries
2021-11-29 15:11:29 +01:00
Julien Doutre
34d1729c5f
unset service case handling
2021-11-29 11:55:50 +01:00
Julien Doutre
5c91a1ab42
fix attribute check logic
2021-11-25 16:14:02 +01:00
Julien Doutre
0abb360f99
Support index backend option
2021-11-23 18:11:46 +01:00
Tim Shelton
ad75a9a5bf
updating hawk backend to provide additional tag enrichment. helps manage the state of each sigma rule, if experimental or not
2021-11-23 16:57:43 +00:00
Julien Doutre
81d3756008
Simple rules support
2021-11-23 17:51:03 +01:00
Anna Pauxberger
c2b91c58d9
add datadog backend structure
2021-11-23 11:08:27 -05:00
frack113
4425f9cbcd
Update sigma2attack.py
2021-11-20 19:59:57 +01:00
frack113
17296b4f5c
Fix score error
2021-11-20 11:13:18 +01:00
frack113
1186982172
Add missing info
2021-11-20 10:10:17 +01:00
frack113
64d7386b9d
Update and fix sigma2attack
2021-11-20 09:55:51 +01:00
redsand (Tim Shelton)
bc334ab456
Hawk backend support for wildcard in middle of string ( #2273 )
...
* updating yaml cfg for ms eventlog support
* update config and sigma backend, so that comments are not replaced, but rather the details of the record
* updating scriptblocktext to value
* adding a few missing ip address translations
* Fixing error when handling comparisons of null values, and additional fix of lack of support for not
* adding additional translations for missing category entries
* fixing error when handling list of ors with a not indicator
* finishes support for windows translations, pending qa
* adding dedupe feature and additional translation fix for dns-server
* adding image_loaded translation
* forced to pull back on the aggressive deduping, caused some inaccuracies
* adding more ux friendly formatting for regex
* adds support for wildcards in middle of strings
* adding a missing null check for supporting null matching
* adding cisco, av, and django cfg in yaml. updated apache in yaml and added another translation for ip_dport
2021-11-18 06:29:41 +01:00
Sven Scharmentke
c09b1861ec
Merge branch 'SigmaHQ:master' into feature/uberagent-compat-6.2
2021-11-17 16:30:05 +01:00
Thomas Patzke
ad647a6ecb
Merge pull request #2240 from Entropy0/bugfix/condition-type-inheritance
...
fix condition token inheritance
2021-11-15 23:43:53 +01:00
Thomas Patzke
cdaefbff69
Merge pull request #2265 from SigmaHQ/fix-ids
...
Additional characters in identifier token
2021-11-15 23:26:28 +01:00
Thomas Patzke
aa47b88326
Merge pull request #2264 from roysjosh/fix-agg-ge-le
...
Fix aggregation GE/LE
2021-11-15 22:51:14 +01:00
Thomas Patzke
068255fc82
Additional characters in identifier token
2021-11-15 22:46:22 +01:00
Joshua Roys
87f919d0bc
Fix aggregation GE/LE
...
List longest matches first otherwise they will never match.
2021-11-15 15:57:46 -05:00
wagga40
a8d00385c3
Fix double quotes escaping and values with commas in SQLite/SQL backends
2021-11-11 20:55:01 +01:00
redsand (Tim Shelton)
a9b49679d3
Updates to hawk sigmac backend ( #2244 )
...
Updated HAWK sigma backend
2021-11-11 08:01:53 +01:00
ZikyHD
510da0085e
Update sysmon.py ( #2234 )
...
Update sysmon.py and merge from master
2021-11-10 20:43:13 +01:00
Entropy0
c7259b6196
fix condition token inheritance
...
Without this fix, isinstance(ConditionOR(), ConditionAND) yields True
2021-11-09 13:19:53 +01:00
Sven Scharmentke
075419da38
Initial commit of pending changes providing uberAgent 6.2 compatibilitz.
2021-11-09 03:38:12 +01:00
frack113
7f087797d6
Merge pull request #2175 from frack113/elastic_is_bad_in_regex
...
manage start end regex for Elastic
2021-11-05 12:27:18 +01:00
Jordi Schoots
23ed626287
Change location value=str(value)
2021-11-01 16:05:34 +01:00
Jordi Schoots
9d0123e782
Fix errors introduced at commit 58d9e41
2021-11-01 12:40:41 +01:00
frack113
f4b1dcfc72
cleanup code
2021-10-28 20:56:19 +02:00
frack113
c49b0d49fa
Add deprecated status
2021-10-28 20:08:27 +02:00
frack113
e9d163cdd1
add filter not status
2021-10-28 19:46:36 +02:00
Tim Shelton
9b6be31c8d
commenting out exceptions output from handling
2021-10-26 18:25:23 +00:00
Tim Shelton
7fc2a6f00d
missed one
2021-10-26 15:25:11 +00:00
Tim Shelton
0d65dcdc28
fixx err
2021-10-26 15:12:03 +00:00
Tim Shelton
22b64644ef
updating hawk backend to fix open ended backslash for regex
2021-10-26 15:09:47 +00:00
Tim Shelton
bacdf53236
updating hawk backend to fix or list map missing an outer and operator
2021-10-26 15:05:27 +00:00
Tim Shelton
6b5c63e485
Merge branch 'master' of https://github.com/redsand/sigma into HAWK_Backend
2021-10-25 18:39:48 +00:00
davedhoff
e772dbf0a9
Import Iterable from collections.abc
2021-10-22 13:56:47 -05:00
frack113
bb758bdb0f
manage start end regex
2021-10-20 21:20:04 +02:00
Tim Shelton
e97fa8fc75
merging from upstream
2021-10-19 02:37:53 +00:00
Tim Shelton
d5498eecbf
updating hawk backend, still pending aggregation support
2021-10-19 02:35:45 +00:00
Tim Shelton
16a78187bd
updating hawk json format record
2021-10-18 21:39:49 +00:00
Tim Shelton
6e35c031de
Add additional information to the analytic record, including tags, author info, rule id and references
2021-10-18 21:39:49 +00:00
Tim Shelton
f2d9cf0964
Initial commmit of hawk analytic score generator
2021-10-18 21:39:49 +00:00
Tim Shelton
ae2923bdd8
Initial commmit of hawk analytic score generator
2021-10-18 21:39:49 +00:00