Feature/addruletype to sigma rule#230 (#235)
* added ruletype to SIGMA rule #230 * added ruletype to SIGMA rule converter tool #231
This commit is contained in:
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1095
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.006
|
||||
- attack.t1028
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1074.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.impact
|
||||
- attack.t1490
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1086
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.t1059.001
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1070.003
|
||||
- attack.t1146
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1140
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1115
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1095
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.006
|
||||
- attack.t1028
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1074.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -92,3 +92,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -70,3 +70,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1106
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1119
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.t1069.001
|
||||
- attack.t1069.002
|
||||
- attack.t1069
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1216
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1216
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1216
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1216
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1136.001
|
||||
- attack.t1136
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1560
|
||||
- attack.t1002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1497.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -23,3 +23,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1048.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -22,3 +22,4 @@ status: test
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1548
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ tags:
|
||||
- attack.t1027
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1056.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -121,3 +121,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -44,3 +44,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ references:
|
||||
status: experimental
|
||||
tags:
|
||||
- attack.t1003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -94,3 +94,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -147,3 +147,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -25,3 +25,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -23,3 +23,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1518
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1564.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1074.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1552.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -92,3 +92,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1114.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1070.005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1119
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -23,3 +23,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1120
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1564.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1070.006
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1546.013
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1547.004
|
||||
- attack.t1004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1546.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -42,3 +42,4 @@ tags:
|
||||
- attack.t1047
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
Reference in New Issue
Block a user