Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEATURE] Keep OpenSearch Security Plugin SIGMA rules up to date as of Dec 2023 #838

Open
hoang-vo opened this issue Feb 6, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@hoang-vo
Copy link

hoang-vo commented Feb 6, 2024

As a security analyst and operator,

I want to utilise up-to-date SIGMA rules in the OpenSearch Security Plugin, so that I can utilise current contributions from the opensource community.

For example - at the time of writing this - the Okta rules in Security Plugin repo (main branch) have not been updated since February 2023 - with 13 rules available , while the SIGMA repo (master branch) Okta rules were last updated in December 2023 - with 21 rules available, notably including rules based on the high-profile Okta breach in 2023.

@hoang-vo hoang-vo added enhancement New feature or request untriaged labels Feb 6, 2024
riysaxen-amzn pushed a commit to riysaxen-amzn/security-analytics that referenced this issue Feb 20, 2024
Signed-off-by: Amardeepsingh Siglani <amardeep7194@gmail.com>
@praveensameneni
Copy link
Member

Thank you @hoang-vo for the request. We plan to update the rules in 2.13 and have an open PR for continuous updates

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants