From ac3ea7b20b5e29be5b18b3c2c2e9a5ae8b8fcf67 Mon Sep 17 00:00:00 2001 From: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com> Date: Sun, 14 Nov 2021 11:00:17 +0900 Subject: [PATCH] hayabusa backend documentation update --- tools/sigmac/README-English.md | 6 +++++- tools/sigmac/README-Japanese.md | 7 ++++++- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/tools/sigmac/README-English.md b/tools/sigmac/README-English.md index 3b1a7a00..e8d84710 100644 --- a/tools/sigmac/README-English.md +++ b/tools/sigmac/README-English.md @@ -87,4 +87,8 @@ win_susp_failed_logons_single_source_ntlm.yml win_susp_failed_logons_single_source_ntlm2.yml win_susp_failed_remote_logons_single_source.yml win_susp_samr_pwset.yml -``` \ No newline at end of file +``` + +## Sigma rule parsing errors + +Some rules will have been able to be converted but will cause parsing errors. We will continue to fix these bugs but for the meantime the majority of Sigma rules do work so please ignore the errors for now. \ No newline at end of file diff --git a/tools/sigmac/README-Japanese.md b/tools/sigmac/README-Japanese.md index b2cc4bba..3556d3d6 100644 --- a/tools/sigmac/README-Japanese.md +++ b/tools/sigmac/README-Japanese.md @@ -87,4 +87,9 @@ win_susp_failed_logons_single_source_ntlm.yml win_susp_failed_logons_single_source_ntlm2.yml win_susp_failed_remote_logons_single_source.yml win_susp_samr_pwset.yml -``` \ No newline at end of file +``` + +## Sigmaルールのパースエラーについて + +一部のルールは変換できたものの、パースエラーが発生しています。 +これらのバグは引き続き修正していきますが、当面はSigmaのルールの大部分は動作しますので、今のところエラーは無視してください。 \ No newline at end of file