Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Support for Sigma Rules #106

Merged
merged 16 commits into from
Jun 27, 2023

Conversation

rc-csmith
Copy link
Contributor

@rc-csmith rc-csmith commented May 9, 2023

Changes

  • Create two options:
    • --sigmarule allows user to specify a single file
    • --sigmadir allows user to specify a directory of Sigma rule files
  • Add extended requirements to support Sigma conversion (but do not make Sigma dependencies a requirement to run Surveyor)
  • Added type checking to GitHub workflow

To Do:

  • Update documentation on how to use the new Sigma options
  • Document limitations of Sigma (no support for Cortex XDR)

@rc-csmith rc-csmith linked an issue May 9, 2023 that may be closed by this pull request
8 tasks
@rc-csmith rc-csmith marked this pull request as ready for review May 24, 2023 13:29
@rc-csmith rc-csmith linked an issue May 26, 2023 that may be closed by this pull request
8 tasks
@rc-csmith rc-csmith self-assigned this May 30, 2023
@rc-abodkins rc-abodkins self-requested a review June 27, 2023 18:47
@rc-csmith rc-csmith merged commit eafdfff into redcanaryco:master Jun 27, 2023
@rc-csmith rc-csmith deleted the 105_sigma_rule_support branch June 27, 2023 18:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[FR] Add Support for Sigma Rules [FR] Implement MyPy
2 participants