Closed thomaspatzke closed 2 years ago
Would you like to change the title to "Rework rules which aren't bound to a field" so it matches with your description and not having that scary "remove" in it ;)
I'll try to work through some of them and will create PRs and link them so you're able to strike them through in your list above.
Fixed rules
New rules identified
Issues
Would you like to change the title to "Rework rules which aren't bound to a field" so it matches with your description and not having that scary "remove" in it ;)
Oh! :grin: Just changed it!
I'll try to work through some of them and will create PRs and link them so you're able to strike them through in your list above.
Thanks a lot!
@thomaspatzke I changed all the windows rules where we mostly know from existing rules which fields exist or which field is available by default - but for all the linux, application and web rules I don't know the used fields and if field extraction is used at all. Mostly the raw events are just indexed into log systems.
I unassign the issue and hope someone can jump in here to fix some of the remaining rules.
See https://github.com/Neo23x0/sigma/issues/501#issuecomment-547570317 for the progress of fixed rules and output of the work I've done so far.
Sorry this post is closed automatically because it is not more active
Rules which aren't bound to fields should be reworked to search on fields as much as possible. These rules are problematic in various ways:
Rules identified so far: