8d6a507ec4
* Checked all rules against Mordor and EVTX samples datasets * Added field names * Some severity adjustments * Fixes
This package contains libraries for processing of Sigma rules and the following command line tools:
- sigmac: converter between Sigma rules and SIEM queries:
- Elasticsearch query strings
- Kibana JSON with searches
- Splunk SPL queries
- Elasticsearch X-Pack Watcher
- Logpoint queries
- merge_sigma: Merge Sigma collections into simple Sigma rules.
- sigma2misp: Import Sigma rules to MISP events.