2020-02-06 11:02:22 +07:00
2020-02-04 18:14:40 +07:00
2019-04-11 18:27:52 +02:00
2020-02-04 18:14:40 +07:00
2019-08-25 10:13:11 +02:00
2020-02-06 11:02:22 +07:00
2017-03-05 01:06:36 +01:00
2017-03-14 12:52:11 +01:00
2019-08-01 23:45:07 +02:00
2019-08-09 14:43:29 +02:00
2019-08-09 14:43:29 +02:00
2019-11-28 04:56:05 -05:00

  1. Sửa host và API Token trong code:
  • Đường dẫn: sigma/tools/sigma/backends/carbonblack.py - line 145.

url = host CarbonBlack

X-Auth-Token = API Token từ profile admin

  1. Chạy lệnh gọi chuyển rules lên watchlist qua API:

    cd /sigma/tools

    python3 sigmac -t carbonblack -c carbonblack -r

Example:

python3 sigmac  -t carbonblack -c carbonblack -r /sigmaRules_tuned
S
Description
Blue team tooling - detection rules, forensics, SIEM content
Readme 51 MiB
Languages
Python 94.4%
Shell 5.6%