SigmaHQ/tools
Thomas Patzke d8e036f737 sigmac: Parameter for ignoring "not supported" errors
Used to pass tests with complete rule set that would fail for backends
which target systems don't support required features.
2018-06-22 00:23:59 +02:00
..
config Added field name mappings to HELK configuration 2018-03-27 14:41:02 +02:00
sigma Added Windows Defender ATP backend 2018-06-22 00:03:10 +02:00
merge_sigma Finalizing PyPI release 2017-12-08 23:50:08 +01:00
README.md Added PyPI README 2017-12-09 22:13:25 +01:00
requirements-devel.txt Python rewrite of es-qs query test 2018-04-11 23:59:44 +02:00
requirements.txt Intermediate refactoring commit: moving code into package 2017-12-08 21:45:05 +01:00
setup.cfg Intermediate refactoring commit: moving code into package 2017-12-08 21:45:05 +01:00
setup.py Sigma tools release 0.4 2018-05-01 00:50:07 +02:00
sigmac sigmac: Parameter for ignoring "not supported" errors 2018-06-22 00:23:59 +02:00

This package contains libraries for processing of Sigma rules and the following command line tools:

  • sigmac: converter between Sigma rules and SIEM queries:
    • Elasticsearch query strings
    • Kibana JSON with searches
    • Splunk SPL queries
    • Elasticsearch X-Pack Watcher
    • Logpoint queries
  • merge_sigma: Merge Sigma collections into simple Sigma rules.