Yamato-Security / sigma-to-hayabusa-converter

Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.
GNU General Public License v3.0
2 stars 0 forks source link

Comments missing #2

Open YamatoSecurity opened 3 months ago

YamatoSecurity commented 3 months ago

Screenshot 2024-05-03 at 08 12 10

On the left are our converted rule and the right has the original sigma rule. There seems to be a missing comment: Note: In the case of... @fukusuket Whenever you have time, could you see if you can keep these comments as well?

Also, - 'ping' gets converted to - ping which is still valid YAML so is no problem, but would like to still keep the single quotes intact if it is not difficult to do.