Feature/addruletype to sigma rule#230 (#235)

* added ruletype to SIGMA rule #230

* added ruletype to SIGMA rule converter tool #231
This commit is contained in:
DustInDark
2021-11-28 18:14:51 +09:00
committed by GitHub
parent bc230f7cd5
commit 0cfa806baf
1087 changed files with 1186 additions and 90 deletions

View File

@@ -37,3 +37,4 @@ status: experimental
tags: tags:
- attack.discovery - attack.discovery
- attack.t1012 - attack.t1012
ruletype: SIGMA

View File

@@ -39,3 +39,4 @@ status: experimental
tags: tags:
- attack.discovery - attack.discovery
- attack.t1012 - attack.t1012
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ status: experimental
tags: tags:
- attack.persistence - attack.persistence
- attack.t1098 - attack.t1098
ruletype: SIGMA

View File

@@ -41,3 +41,4 @@ tags:
- attack.discovery - attack.discovery
- attack.t1087 - attack.t1087
- attack.t1087.002 - attack.t1087.002
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1222 - attack.t1222
- attack.t1222.001 - attack.t1222.001
ruletype: SIGMA

View File

@@ -39,3 +39,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.t1003 - attack.t1003
- attack.t1003.006 - attack.t1003.006
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ tags:
- attack.discovery - attack.discovery
- attack.t1087 - attack.t1087
- attack.t1087.002 - attack.t1087.002
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ status: experimental
tags: tags:
- attack.privilege_escalation - attack.privilege_escalation
- attack.credential_access - attack.credential_access
ruletype: SIGMA

View File

@@ -46,3 +46,4 @@ status: experimental
tags: tags:
- attack.privilege_escalation - attack.privilege_escalation
- attack.credential_access - attack.credential_access
ruletype: SIGMA

View File

@@ -34,3 +34,4 @@ tags:
- attack.t1078.002 - attack.t1078.002
- attack.t1078.003 - attack.t1078.003
- car.2016-04-005 - car.2016-04-005
ruletype: SIGMA

View File

@@ -26,3 +26,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1077 - attack.t1077
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ status: experimental
tags: tags:
- attack.persistence - attack.persistence
- attack.t1098 - attack.t1098
ruletype: SIGMA

View File

@@ -50,3 +50,4 @@ status: experimental
tags: tags:
- attack.t1098 - attack.t1098
- attack.persistence - attack.persistence
ruletype: SIGMA

View File

@@ -88,3 +88,4 @@ tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1089 - attack.t1089
- attack.t1562.001 - attack.t1562.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.t1003 - attack.t1003
- attack.t1003.001 - attack.t1003.001
ruletype: SIGMA

View File

@@ -43,3 +43,4 @@ tags:
- attack.t1003.004 - attack.t1003.004
- attack.t1003.001 - attack.t1003.001
- attack.t1003.006 - attack.t1003.006
ruletype: SIGMA

View File

@@ -38,3 +38,4 @@ tags:
- attack.t1114 - attack.t1114
- attack.t1059 - attack.t1059
- attack.t1550.002 - attack.t1550.002
ruletype: SIGMA

View File

@@ -45,3 +45,4 @@ tags:
- attack.t1059.005 - attack.t1059.005
- attack.t1059.006 - attack.t1059.006
- attack.t1059.007 - attack.t1059.007
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.g0010 - attack.g0010
- attack.t1050 - attack.t1050
- attack.t1543.003 - attack.t1543.003
ruletype: SIGMA

View File

@@ -39,3 +39,4 @@ tags:
- attack.command_and_control - attack.command_and_control
- attack.t1071 - attack.t1071
- attack.t1071.004 - attack.t1071.004
ruletype: SIGMA

View File

@@ -36,3 +36,4 @@ tags:
- attack.command_and_control - attack.command_and_control
- attack.t1071 - attack.t1071
- attack.t1071.004 - attack.t1071.004
ruletype: SIGMA

View File

@@ -36,3 +36,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.command_and_control - attack.command_and_control
- attack.t1071 - attack.t1071
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ tags:
- attack.persistence - attack.persistence
- attack.t1053 - attack.t1053
- attack.s0111 - attack.s0111
ruletype: SIGMA

View File

@@ -27,3 +27,4 @@ tags:
- attack.g0064 - attack.g0064
- attack.t1050 - attack.t1050
- attack.t1543.003 - attack.t1543.003
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.g0010 - attack.g0010
- attack.t1050 - attack.t1050
- attack.t1543.003 - attack.t1543.003
ruletype: SIGMA

View File

@@ -35,3 +35,4 @@ tags:
- attack.t1053 - attack.t1053
- attack.t1059.001 - attack.t1059.001
- attack.t1086 - attack.t1086
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ tags:
- attack.t1566.001 - attack.t1566.001
- attack.execution - attack.execution
- attack.initial_access - attack.initial_access
ruletype: SIGMA

View File

@@ -27,3 +27,4 @@ tags:
- attack.t1218 - attack.t1218
- attack.defense_evasion - attack.defense_evasion
- attack.execution - attack.execution
ruletype: SIGMA

View File

@@ -33,3 +33,4 @@ tags:
- car.2013-05-004 - car.2013-05-004
- car.2015-04-001 - car.2015-04-001
- attack.t1053.002 - attack.t1053.002
ruletype: SIGMA

View File

@@ -36,3 +36,4 @@ tags:
- attack.t1210 - attack.t1210
- attack.impact - attack.impact
- attack.t1499.004 - attack.t1499.004
ruletype: SIGMA

View File

@@ -41,3 +41,4 @@ status: experimental
tags: tags:
- attack.resource_development - attack.resource_development
- attack.t1588 - attack.t1588
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ status: experimental
tags: tags:
- attack.collection - attack.collection
- attack.t1123 - attack.t1123
ruletype: SIGMA

View File

@@ -46,3 +46,4 @@ tags:
- attack.t1021.002 - attack.t1021.002
- attack.t1543.003 - attack.t1543.003
- attack.t1569.002 - attack.t1569.002
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ status: experimental
tags: tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

View File

@@ -27,3 +27,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1021.002 - attack.t1021.002
- attack.t1021.003 - attack.t1021.003
ruletype: SIGMA

View File

@@ -38,3 +38,4 @@ tags:
- attack.s0002 - attack.s0002
- attack.t1003 - attack.t1003
- attack.t1003.006 - attack.t1003.006
ruletype: SIGMA

View File

@@ -37,3 +37,4 @@ tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1054 - attack.t1054
- attack.t1562.002 - attack.t1562.002
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.t1003 - attack.t1003
- attack.t1003.004 - attack.t1003.004
ruletype: SIGMA

View File

@@ -26,3 +26,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.t1003 - attack.t1003
- attack.t1003.004 - attack.t1003.004
ruletype: SIGMA

View File

@@ -34,3 +34,4 @@ status: experimental
tags: tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1112 - attack.t1112
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ status: experimental
tags: tags:
- attack.t1107 - attack.t1107
- attack.t1070.001 - attack.t1070.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ status: experimental
tags: tags:
- attack.persistence - attack.persistence
- attack.t1505.002 - attack.t1505.002
ruletype: SIGMA

View File

@@ -43,3 +43,4 @@ tags:
- attack.execution - attack.execution
- attack.t1569 - attack.t1569
- cve.2021.1675 - cve.2021.1675
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ tags:
- attack.execution - attack.execution
- attack.t1569 - attack.t1569
- cve.2021.1675 - cve.2021.1675
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ tags:
- attack.t1569 - attack.t1569
- cve.2021.1675 - cve.2021.1675
- cve.2021.34527 - cve.2021.34527
ruletype: SIGMA

View File

@@ -26,3 +26,4 @@ tags:
- attack.t1200 - attack.t1200
- attack.lateral_movement - attack.lateral_movement
- attack.initial_access - attack.initial_access
ruletype: SIGMA

View File

@@ -31,3 +31,4 @@ tags:
- attack.discovery - attack.discovery
- attack.t1087 - attack.t1087
- attack.t1087.002 - attack.t1087.002
ruletype: SIGMA

View File

@@ -35,3 +35,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1053 - attack.t1053
- attack.t1053.005 - attack.t1053.005
ruletype: SIGMA

View File

@@ -33,3 +33,4 @@ tags:
- attack.t1021.002 - attack.t1021.002
- attack.t1035 - attack.t1035
- attack.t1569.002 - attack.t1569.002
ruletype: SIGMA

View File

@@ -26,3 +26,4 @@ status: experimental
tags: tags:
- attack.persistence - attack.persistence
- attack.t1136.001 - attack.t1136.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ status: experimental
tags: tags:
- attack.persistence - attack.persistence
- attack.t1554 - attack.t1554
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ status: experimental
tags: tags:
- attack.persistence - attack.persistence
- attack.t1554 - attack.t1554
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ status: experimental
tags: tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ tags:
- attack.t1003.002 - attack.t1003.002
- attack.t1003.004 - attack.t1003.004
- attack.t1003.003 - attack.t1003.003
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -35,3 +35,4 @@ status: experimental
tags: tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1027 - attack.t1027
ruletype: SIGMA

View File

@@ -40,3 +40,4 @@ status: experimental
tags: tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1027 - attack.t1027
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.t1027 - attack.t1027
- attack.execution - attack.execution
- attack.t1059.001 - attack.t1059.001
ruletype: SIGMA

View File

@@ -34,3 +34,4 @@ status: experimental
tags: tags:
- attack.initial_access - attack.initial_access
- attack.t1566.001 - attack.t1566.001
ruletype: SIGMA

View File

@@ -51,3 +51,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1077 - attack.t1077
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ tags:
- attack.t1482 - attack.t1482
- attack.t1018 - attack.t1018
- attack.t1016 - attack.t1016
ruletype: SIGMA

View File

@@ -67,3 +67,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.t1003 - attack.t1003
- attack.t1003.001 - attack.t1003.001
ruletype: SIGMA

View File

@@ -40,3 +40,4 @@ tags:
- attack.t1035 - attack.t1035
- attack.t1569.002 - attack.t1569.002
- attack.s0005 - attack.s0005
ruletype: SIGMA

View File

@@ -31,3 +31,4 @@ tags:
- attack.credential_access - attack.credential_access
- attack.t1003 - attack.t1003
- attack.s0005 - attack.s0005
ruletype: SIGMA

View File

@@ -37,3 +37,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1077 - attack.t1077
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

View File

@@ -63,3 +63,4 @@ tags:
- attack.t1134 - attack.t1134
- attack.t1134.001 - attack.t1134.001
- attack.t1134.002 - attack.t1134.002
ruletype: SIGMA

View File

@@ -31,3 +31,4 @@ tags:
- attack.execution - attack.execution
- attack.t1175 - attack.t1175
- attack.t1021.003 - attack.t1021.003
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ tags:
- attack.persistence - attack.persistence
- attack.privilege_escalation - attack.privilege_escalation
- attack.t1543.003 - attack.t1543.003
ruletype: SIGMA

View File

@@ -38,3 +38,4 @@ tags:
- attack.t1089 - attack.t1089
- attack.t1562.001 - attack.t1562.001
- attack.t1112 - attack.t1112
ruletype: SIGMA

View File

@@ -30,3 +30,4 @@ status: experimental
tags: tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

View File

@@ -27,3 +27,4 @@ status: experimental
tags: tags:
- attack.defense_evasion - attack.defense_evasion
- attack.t1036 - attack.t1036
ruletype: SIGMA

View File

@@ -28,3 +28,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1076 - attack.t1076
- attack.t1021.001 - attack.t1021.001
ruletype: SIGMA

View File

@@ -31,3 +31,4 @@ status: experimental
tags: tags:
- attack.impact - attack.impact
- attack.t1499.001 - attack.t1499.001
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ tags:
- attack.t1075 - attack.t1075
- attack.s0002 - attack.s0002
- attack.t1550.002 - attack.t1550.002
ruletype: SIGMA

View File

@@ -40,3 +40,4 @@ tags:
- attack.t1075 - attack.t1075
- car.2016-04-004 - car.2016-04-004
- attack.t1550.002 - attack.t1550.002
ruletype: SIGMA

View File

@@ -42,3 +42,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1075 - attack.t1075
- attack.t1550.002 - attack.t1550.002
ruletype: SIGMA

View File

@@ -31,3 +31,4 @@ status: experimental
tags: tags:
- attack.credential_access - attack.credential_access
- attack.t1187 - attack.t1187
ruletype: SIGMA

View File

@@ -41,3 +41,4 @@ status: experimental
tags: tags:
- attack.credential_access - attack.credential_access
- attack.t1187 - attack.t1187
ruletype: SIGMA

View File

@@ -32,3 +32,4 @@ status: experimental
tags: tags:
- attack.credential_access - attack.credential_access
- attack.t1207 - attack.t1207
ruletype: SIGMA

View File

@@ -25,3 +25,4 @@ status: experimental
tags: tags:
- attack.execution - attack.execution
- attack.t1569.002 - attack.t1569.002
ruletype: SIGMA

View File

@@ -29,3 +29,4 @@ status: experimental
tags: tags:
- attack.t1068 - attack.t1068
- attack.privilege_escalation - attack.privilege_escalation
ruletype: SIGMA

View File

@@ -27,3 +27,4 @@ tags:
- attack.lateral_movement - attack.lateral_movement
- attack.t1021 - attack.t1021
- attack.t1021.002 - attack.t1021.002
ruletype: SIGMA

Some files were not shown because too many files have changed in this diff Show More