Files
blue-team-tools/tools
Thomas Patzke 1c5c8047fd Fixes
* Removed commented debug print statements
* Defined nullExpression
* Removed unneeded generateMapItemNode method
* Value cleaning bug on matching of wildcard at first character
2020-04-08 23:43:46 +02:00
..
2020-04-08 23:43:46 +02:00
2018-07-27 00:02:07 +02:00
2019-05-30 22:56:38 +02:00
2020-03-29 22:55:09 +02:00
2020-02-25 22:19:52 +01:00
2019-12-19 00:00:13 +01:00
2019-11-11 23:35:16 +01:00
2020-02-20 18:55:10 +09:00
2019-11-12 23:37:28 +01:00
2020-04-08 23:23:44 +02:00

This package contains libraries for processing of Sigma rules and the following command line tools:

  • sigmac: converter between Sigma rules and SIEM queries:
    • Elasticsearch query strings
    • Kibana JSON with searches
    • Splunk SPL queries
    • Elasticsearch X-Pack Watcher
    • Logpoint queries
  • merge_sigma: Merge Sigma collections into simple Sigma rules.
  • sigma2misp: Import Sigma rules to MISP events.