SigmaHQ/tools/README.md

12 lines
463 B
Markdown
Raw Normal View History

2017-12-09 21:13:25 +00:00
This package contains libraries for processing of [Sigma rules](https://github.com/Neo23x0/sigma) and the following
command line tools:
* *sigmac*: converter between Sigma rules and SIEM queries:
* Elasticsearch query strings
* Kibana JSON with searches
* Splunk SPL queries
* Elasticsearch X-Pack Watcher
* Logpoint queries
* *merge_sigma*: Merge Sigma collections into simple Sigma rules.
2019-05-30 20:47:03 +00:00
* *sigma2misp*: Import Sigma rules to MISP events.