SecurityRiskAdvisors / VECTR

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
1.4k stars 165 forks source link

Import Sigma Rules #101

Open txapel91 opened 4 years ago

txapel91 commented 4 years ago

I'd like to import Sigma rules (ideally on bulk) as to keep the internal repository up to date in a semi-automated fashion. Is there a way to do this?

carlvonderheid commented 3 years ago

Unfortunately not yet. We have revamping Detection Rules as a priority in 2021 on our roadmap, which should address this. I'll make a note that we should update to the latest Sigma Rules for the next release, and hopefully we can do this with more frequency until we allow users to do it manually or through automation.