Yamato-Security / sigma-to-hayabusa-converter

Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.
GNU General Public License v3.0
2 stars 0 forks source link

Explain the conversion process in more details #7

Open YamatoSecurity opened 2 months ago

YamatoSecurity commented 2 months ago

I'd like to explain more about what the conversion is doing in the background and how it maps sysmon fields to windows built in fields and include pictures of the comparisons that we made for process creation and registry rules.