Yamato-Security / suzaku-rules

Other
1 stars 1 forks source link

Import sigma AWS rules #1

Closed YamatoSecurity closed 4 months ago

YamatoSecurity commented 5 months ago

@fukusuket Could I ask you to look into how to automate importing AWS sigma rules into this repository. We can have a suzaku folder for suzaku rules and a sigma folder for sigma rules just like in hayabusa. config directory will hold config files.

Right now, there are only cloudtrail logs in sigma so we can just sync those to ./sigma/aws/cloudtrail/.

fukusuket commented 5 months ago

Yes, I would love to look into!💪