SigmaHQ / sigma

Main Sigma Rule Repository
Other
8.33k stars 2.2k forks source link

Rework rules which aren't bound to a field #501

Closed thomaspatzke closed 2 years ago

thomaspatzke commented 5 years ago

Rules which aren't bound to fields should be reworked to search on fields as much as possible. These rules are problematic in various ways:

Rules identified so far:

Karneades commented 5 years ago

Would you like to change the title to "Rework rules which aren't bound to a field" so it matches with your description and not having that scary "remove" in it ;)

I'll try to work through some of them and will create PRs and link them so you're able to strike them through in your list above.

Karneades commented 5 years ago

Fixed rules

New rules identified

Issues

thomaspatzke commented 5 years ago

Would you like to change the title to "Rework rules which aren't bound to a field" so it matches with your description and not having that scary "remove" in it ;)

Oh! :grin: Just changed it!

I'll try to work through some of them and will create PRs and link them so you're able to strike them through in your list above.

Thanks a lot!

Karneades commented 5 years ago

@thomaspatzke I changed all the windows rules where we mostly know from existing rules which fields exist or which field is available by default - but for all the linux, application and web rules I don't know the used fields and if field extraction is used at all. Mostly the raw events are just indexed into log systems.

I unassign the issue and hope someone can jump in here to fix some of the remaining rules.

See https://github.com/Neo23x0/sigma/issues/501#issuecomment-547570317 for the progress of fixed rules and output of the work I've done so far.

frack113 commented 2 years ago

Sorry this post is closed automatically because it is not more active