Feature/addruletype to sigma rule#230 (#235)
* added ruletype to SIGMA rule #230 * added ruletype to SIGMA rule converter tool #231
This commit is contained in:
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1112
|
||||
- attack.t1053
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1046
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -49,3 +49,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1564.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.t1212
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -46,3 +46,4 @@ tags:
|
||||
- attack.t1212
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1105
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1053.005
|
||||
- attack.s0111
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.t1083
|
||||
- attack.t1135
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -46,3 +46,4 @@ tags:
|
||||
- attack.t1053
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -43,3 +43,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1119
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218.011
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1115
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218.011
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.impact
|
||||
- attack.s0575
|
||||
- attack.t1486
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -42,3 +42,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1552.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -41,3 +41,4 @@ tags:
|
||||
- attack.t1073
|
||||
- attack.t1574.002
|
||||
- attack.t1112
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1567
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ tags:
|
||||
- attack.t1218.010
|
||||
- attack.execution
|
||||
- attack.defense_evasion
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -43,3 +43,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1547
|
||||
- attack.t1547.006
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ tags:
|
||||
- attack.t1218.010
|
||||
- attack.execution
|
||||
- attack.defense_evasion
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ tags:
|
||||
- attack.t1218.010
|
||||
- attack.execution
|
||||
- attack.defense_evasion
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -56,3 +56,4 @@ tags:
|
||||
- attack.t1218.010
|
||||
- attack.execution
|
||||
- attack.defense_evasion
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -52,3 +52,4 @@ tags:
|
||||
- attack.t1218.010
|
||||
- attack.execution
|
||||
- attack.defense_evasion
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.t1218.010
|
||||
- attack.execution
|
||||
- attack.defense_evasion
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1574.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1553.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.impact
|
||||
- attack.t1485
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -38,3 +38,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1518
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -42,3 +42,4 @@ tags:
|
||||
- attack.t1546.008
|
||||
- car.2014-11-003
|
||||
- car.2014-11-008
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1560.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -39,3 +39,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1070.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1119
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
- attack.t1086
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1560.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.collection
|
||||
- attack.t1074.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
- attack.t1216
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.resource_development
|
||||
- attack.t1588.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.t1088
|
||||
- attack.t1548.002
|
||||
- car.2019-04-001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ tags:
|
||||
- attack.t1035
|
||||
- attack.t1569.002
|
||||
- attack.s0029
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -26,3 +26,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1505.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ tags:
|
||||
- attack.t1505.003
|
||||
- attack.resource_development
|
||||
- attack.t1584.006
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003
|
||||
- attack.t1003.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -48,3 +48,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1548
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1069.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1548.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -44,3 +44,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1548.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
- attack.t1071.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -46,3 +46,4 @@ tags:
|
||||
- attack.t1546.015
|
||||
- attack.persistence
|
||||
- attack.privilege_escalation
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -36,3 +36,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1190
|
||||
- attack.t1059
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ tags:
|
||||
- attack.t1218.003
|
||||
- attack.g0069
|
||||
- car.2019-04-001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.collection
|
||||
- attack.t1218
|
||||
- attack.t1056.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.t1203
|
||||
- attack.execution
|
||||
- cve.2021.26857
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -36,3 +36,4 @@ tags:
|
||||
- attack.t1003
|
||||
- attack.t1003.001
|
||||
- attack.s0005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.defense_evasion
|
||||
- attack.t1548.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -36,3 +36,4 @@ tags:
|
||||
- attack.t1037
|
||||
- attack.t1037.001
|
||||
- attack.persistence
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1095
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -37,3 +37,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -33,3 +33,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -24,3 +24,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.t1548.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.t1572
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1048.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -32,3 +32,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -43,3 +43,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.persistence
|
||||
- attack.t1059
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -56,3 +56,4 @@ tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1071
|
||||
- attack.t1071.004
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -45,3 +45,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.t1482
|
||||
- attack.t1018
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ references:
|
||||
status: experimental
|
||||
tags:
|
||||
- attack.t1219
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -34,3 +34,4 @@ tags:
|
||||
- attack.t1086
|
||||
- attack.t1059
|
||||
- attack.t1059.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.t1170
|
||||
- attack.t1218
|
||||
- attack.t1218.005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -49,3 +49,4 @@ tags:
|
||||
- attack.t1003
|
||||
- attack.t1552.001
|
||||
- attack.t1003.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1117
|
||||
- attack.t1218.010
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.g0045
|
||||
- attack.t1064
|
||||
- attack.t1059.005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -27,3 +27,4 @@ tags:
|
||||
- attack.discovery
|
||||
- attack.t1110
|
||||
- attack.t1087
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1059
|
||||
- attack.t1059.003
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1073
|
||||
- attack.t1574.002
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -28,3 +28,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1218.010
|
||||
- attack.t1117
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -31,3 +31,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1085
|
||||
- attack.t1218.011
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -35,3 +35,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1085
|
||||
- attack.t1218.011
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -60,3 +60,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1036
|
||||
- attack.t1036.005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -91,3 +91,4 @@ tags:
|
||||
- attack.persistence
|
||||
- attack.t1546
|
||||
- attack.t1053
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.g0009
|
||||
- attack.t1068
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -41,3 +41,4 @@ tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1002
|
||||
- attack.t1560.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -29,3 +29,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1089
|
||||
- attack.t1562.001
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -40,3 +40,4 @@ tags:
|
||||
- attack.g0032
|
||||
- attack.execution
|
||||
- attack.t1106
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -43,3 +43,4 @@ tags:
|
||||
- attack.g0032
|
||||
- attack.execution
|
||||
- attack.t1059
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -45,3 +45,4 @@ tags:
|
||||
- attack.g0032
|
||||
- attack.execution
|
||||
- attack.t1059
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -30,3 +30,4 @@ tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1036
|
||||
- attack.t1036.005
|
||||
ruletype: SIGMA
|
||||
|
||||
@@ -42,3 +42,4 @@ status: experimental
|
||||
tags:
|
||||
- attack.t1587.001
|
||||
- attack.resource_development
|
||||
ruletype: SIGMA
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user