d8a7bcad39
Generation of query parts before and after main query gives access to information possibly gathered while main query generation.
This package contains libraries for processing of Sigma rules and the following command line tools:
- sigmac: converter between Sigma rules and SIEM queries:
- Elasticsearch query strings
- Kibana JSON with searches
- Splunk SPL queries
- Elasticsearch X-Pack Watcher
- Logpoint queries
- merge_sigma: Merge Sigma collections into simple Sigma rules.