atc-project / atomic-threat-coverage

Actionable analytics designed to combat threats
Apache License 2.0
962 stars 155 forks source link

Provide option to use sigma backend config #192

Closed sn0w0tter closed 3 years ago

sn0w0tter commented 4 years ago

Currently we are ignoring sigma backend configs with --shoot-yourself-in-the-foot command switch. ATC should allow user to use config which matches his fields mapping in SIEM.

https://github.com/Neo23x0/sigma/tree/master/tools/config