Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature idea: sigma export #17

Open
ruppde opened this issue Nov 28, 2023 · 4 comments
Open

Feature idea: sigma export #17

ruppde opened this issue Nov 28, 2023 · 4 comments
Assignees
Labels
enhancement New feature or request

Comments

@ruppde
Copy link
Contributor

ruppde commented Nov 28, 2023

hi RMML people,

the perfect addition would be a converter script to sigma (https://github.com/SigmaHQ/sigma) because then sigma could create rules for carbon black and many more security tools like splunk, qradar, azure, ... see https://sigconverter.io/

regards
arnim

@LivingInSyn
Copy link
Owner

Definitely interested in this as the next integration

@devinbfergy devinbfergy self-assigned this Nov 28, 2023
@devinbfergy devinbfergy added the enhancement New feature or request label Nov 28, 2023
@ruppde
Copy link
Contributor Author

ruppde commented Nov 28, 2023

cool!

if you need examples, just search for some of the existing rules, e.g.:
https://github.com/search?q=repo%3ASigmaHQ%2Fsigma%20teamviewer&type=code
https://github.com/search?q=repo%3ASigmaHQ%2Fsigma+anydesk&type=code

@LivingInSyn
Copy link
Owner

@ruppde check out the sigma branch, I'm not sold on converting the rule format to sigma natively yet, but I'm going to try translating them in CI

@ruppde
Copy link
Contributor Author

ruppde commented Sep 23, 2024

fyi, there's a similar project in the works: https://x.com/M_haggis/status/1825947732382712231

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants