Skip to content

Configuration file used for sigma rules conversion #3230

Closed Answered by frack113
Iqi-Malick asked this question in Q&A
Discussion options

You must be logged in to vote

quick answer: no

You would have to write a configuration file with different index.
There may be a way, but it will be a pain.

The easiest way is to make a directory (linux or network or ...) = a mapping file.
ECS mapping other than windows is not very well maintained.
If you find error you can make a PR

Be aware that linux folder is for builtin , auditd or sysmon ...

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Iqi-Malick
Comment options

@thomaspatzke
Comment options

Answer selected by thomaspatzke
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants