Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sigma rules feed.. #1614

Open
necrose99 opened this issue Feb 28, 2023 · 2 comments
Open

Sigma rules feed.. #1614

necrose99 opened this issue Feb 28, 2023 · 2 comments
Assignees

Comments

@necrose99
Copy link

necrose99 commented Feb 28, 2023

https://uncoder.io/

https://github.com/SigmaHQ/sigma

https://github.com/bradleyjkemp/sigma-go
A few free sigma feeds..

While common in siem land , these are more raw threat detections..

Machine a is vulnerable to x..
Warning ⚠️ Machine a is showing active infected.... might be useful to know.. on reports
Your firewall is not patched is vulnerable, compromised etc..

as a 🔌 plug-in ..

Simular to go-cti gost etc..

@MaineK00n
Copy link
Collaborator

I am also interested in the cooperation with Sigma rule.
Similarly, I would like to support Snort, Yara, etc.

The most difficult part of the research is that the amount of data sources is far too small to link the detected CVEs to those rules.
At the time, the most usable rules we found were the officially distributed Snort rules.

Do you know of a data source that is stable, updated and has a reasonable amount of data linking these rules to CVEs?

@MaineK00n MaineK00n self-assigned this Mar 2, 2023
@necrose99
Copy link
Author

necrose99 commented Mar 2, 2023

Least you could at the very least , add it in the yellow ⚠️ category, ie caution.. as posible detections.. ? Sigma rules , unfortunately not an easy sigma2taxii or sigma2stixx , least initially, thier might be more on futher reserch ... consumer io that vuls could injest with current vuls sub-tools.

Least in golang..

https://github.com/opencybersecurityalliance/stix-shifter , ports to stix2

https://pkg.go.dev/github.com/TcM1911/stix2

https://raw.githubusercontent.com/SigmaHQ/sigma/master/tools/config/ecs-suricata.yml , perhaps useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants