Files
blue-team-tools/tools
Thomas Patzke d8a7bcad39 Reordered rule generation
Generation of query parts before and after main query gives access to
information possibly gathered while main query generation.
2018-06-21 23:50:13 +02:00
..
2018-06-21 23:50:13 +02:00
2017-12-08 23:50:08 +01:00
2017-12-09 22:13:25 +01:00
2018-05-01 00:50:07 +02:00
2018-03-21 00:53:44 +01:00

This package contains libraries for processing of Sigma rules and the following command line tools:

  • sigmac: converter between Sigma rules and SIEM queries:
    • Elasticsearch query strings
    • Kibana JSON with searches
    • Splunk SPL queries
    • Elasticsearch X-Pack Watcher
    • Logpoint queries
  • merge_sigma: Merge Sigma collections into simple Sigma rules.