From 7bdaf9338e5d70fea6164c096a6a4adcd247b456 Mon Sep 17 00:00:00 2001 From: Josh Brower Date: Thu, 20 Aug 2026 09:31:56 -0400 Subject: [PATCH] Update Sigma template --- salt/soc/defaults.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 4bb1b0f8b..c5e14d31b 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -2671,7 +2671,7 @@ soc: # The id (UUIDv4) is pregenerated and can safely be used. # Click "Convert" to convert the Sigma rule to use Security Onion field mappings within an EQL query # - # Rule Creation Guide: https://github.com/SigmaHQ/sigma/wiki/Rule-Creation-Guide + # Rule Creation Guide: https://github.com/SigmaHQ/sigma/wiki/Rule-Creation-High%E2%80%90Level-Guide # Logsources: https://sigmahq.io/docs/basics/log-sources.html title: 'A Short Capitalized Title With Less Than 50 Characters' @@ -2683,7 +2683,7 @@ soc: references: - 'https://local.invalid' author: '@SecurityOnion' - date: 'YYYY/MM/DD' + date: '[today]' tags: - detection.threat_hunting - attack.technique_id