When creating a Sigma rule that is intended to be largely (but not always) used with a correlation rule or could be used with multiple different correlation rules, there does not seem to be a good way of indicating that in the Sigma rule metadata itself.
The related field allows us to associate Sigma rules together, but the types available do not seem (to me) to align with the above desired use-case - my suggestion is to introduce a type: correlation or type: recommended_correlation to the standard to enable it.
A simple example usage might look like the following Sigma rule:
When creating a Sigma rule that is intended to be largely (but not always) used with a correlation rule or could be used with multiple different correlation rules, there does not seem to be a good way of indicating that in the Sigma rule metadata itself.
The
related
field allows us to associate Sigma rules together, but thetype
s available do not seem (to me) to align with the above desired use-case - my suggestion is to introduce atype: correlation
ortype: recommended_correlation
to the standard to enable it.A simple example usage might look like the following Sigma rule:
With the associated Sigma correlation rule: