Skip to content

Ruleset

Felix Bauer edited this page May 27, 2020 · 2 revisions

Ruleset

Steps to develop a new rule

From Security Management

PeekabooAV-Rule-development.jpg

From a detected intrusion

  • Virus has been found somewhere
  • Sample is available
  • Analysis of the sample with the desired analyser
  • Manual report evaulation
  • Extraction of IoCs and methodologies
  • Defining the expression rule in Peekaboo