Feature/addruletype to sigma rule#230 (#235)
* added ruletype to SIGMA rule #230 * added ruletype to SIGMA rule converter tool #231
This commit is contained in:
@@ -37,3 +37,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1012
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -39,3 +39,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1012
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1098
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -41,3 +41,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.t1087
|
||||
- attack.t1087.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1222
|
||||
- attack.t1222.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -39,3 +39,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.006
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.t1087
|
||||
- attack.t1087.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.credential_access
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -46,3 +46,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.credential_access
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ tags:
|
||||
- attack.t1078.002
|
||||
- attack.t1078.003
|
||||
- car.2016-04-005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1077
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1098
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -50,3 +50,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.t1098
|
||||
- attack.persistence
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -88,3 +88,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1089
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -43,3 +43,4 @@ tags:
|
||||
- attack.t1003.004
|
||||
- attack.t1003.001
|
||||
- attack.t1003.006
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ tags:
|
||||
- attack.t1114
|
||||
- attack.t1059
|
||||
- attack.t1550.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -45,3 +45,4 @@ tags:
|
||||
- attack.t1059.005
|
||||
- attack.t1059.006
|
||||
- attack.t1059.007
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.g0010
|
||||
- attack.t1050
|
||||
- attack.t1543.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -39,3 +39,4 @@ tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
- attack.t1071.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -36,3 +36,4 @@ tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
- attack.t1071.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -36,3 +36,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1053
|
||||
- attack.s0111
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.g0064
|
||||
- attack.t1050
|
||||
- attack.t1543.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.g0010
|
||||
- attack.t1050
|
||||
- attack.t1543.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.t1053
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.t1566.001
|
||||
- attack.execution
|
||||
- attack.initial_access
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1218
|
||||
- attack.defense_evasion
|
||||
- attack.execution
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ tags:
|
||||
- car.2013-05-004
|
||||
- car.2015-04-001
|
||||
- attack.t1053.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -36,3 +36,4 @@ tags:
|
||||
- attack.t1210
|
||||
- attack.impact
|
||||
- attack.t1499.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -41,3 +41,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.resource_development
|
||||
- attack.t1588
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1123
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -46,3 +46,4 @@ tags:
|
||||
- attack.t1021.002
|
||||
- attack.t1543.003
|
||||
- attack.t1569.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.002
|
||||
- attack.t1021.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ tags:
|
||||
- attack.s0002
|
||||
- attack.t1003
|
||||
- attack.t1003.006
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1054
|
||||
- attack.t1562.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1112
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.t1107
|
||||
- attack.t1070.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1505.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -43,3 +43,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1569
|
||||
- cve.2021.1675
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1569
|
||||
- cve.2021.1675
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.t1569
|
||||
- cve.2021.1675
|
||||
- cve.2021.34527
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ tags:
|
||||
- attack.t1200
|
||||
- attack.lateral_movement
|
||||
- attack.initial_access
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.t1087
|
||||
- attack.t1087.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1053
|
||||
- attack.t1053.005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ tags:
|
||||
- attack.t1021.002
|
||||
- attack.t1035
|
||||
- attack.t1569.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1136.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1554
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1554
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.t1003.002
|
||||
- attack.t1003.004
|
||||
- attack.t1003.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1027
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1027
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.initial_access
|
||||
- attack.t1566.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -51,3 +51,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1077
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.t1482
|
||||
- attack.t1018
|
||||
- attack.t1016
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -67,3 +67,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ tags:
|
||||
- attack.t1035
|
||||
- attack.t1569.002
|
||||
- attack.s0005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.s0005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1077
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -63,3 +63,4 @@ tags:
|
||||
- attack.t1134
|
||||
- attack.t1134.001
|
||||
- attack.t1134.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1175
|
||||
- attack.t1021.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.privilege_escalation
|
||||
- attack.t1543.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ tags:
|
||||
- attack.t1089
|
||||
- attack.t1562.001
|
||||
- attack.t1112
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1036
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1076
|
||||
- attack.t1021.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.impact
|
||||
- attack.t1499.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.t1075
|
||||
- attack.s0002
|
||||
- attack.t1550.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ tags:
|
||||
- attack.t1075
|
||||
- car.2016-04-004
|
||||
- attack.t1550.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -42,3 +42,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1075
|
||||
- attack.t1550.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1187
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -41,3 +41,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1187
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1207
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1569.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.t1068
|
||||
- attack.privilege_escalation
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021
|
||||
- attack.t1021.002
|
||||
ruletype: SIGMA
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user