Files
blue-team-tools/tools
Thomas Patzke 849a5a520d Conditional field mapping resolve_fieldname now functional
Before this method just had some placeholder function that wasn't really
implementing the intended functionality of the conditional field
mapping. Now aggregations get also conditional field mapping
functionality.
2019-10-09 23:57:41 +02:00
..
2019-08-01 23:45:07 +02:00
2018-07-27 00:02:07 +02:00
2019-05-30 22:56:38 +02:00
2018-10-22 22:43:59 +02:00
2018-10-22 22:43:59 +02:00
2019-08-05 23:42:33 +02:00
2019-03-02 00:14:20 +01:00
2018-10-22 23:02:05 +02:00
2019-10-07 22:30:57 +02:00

This package contains libraries for processing of Sigma rules and the following command line tools:

  • sigmac: converter between Sigma rules and SIEM queries:
    • Elasticsearch query strings
    • Kibana JSON with searches
    • Splunk SPL queries
    • Elasticsearch X-Pack Watcher
    • Logpoint queries
  • merge_sigma: Merge Sigma collections into simple Sigma rules.
  • sigma2misp: Import Sigma rules to MISP events.