cisagov / LME

Logging Made Easy (LME) is a no-cost and open logging and protective monitoring solution serving all organizations.
https://www.cisa.gov/resources-tools/services/logging-made-easy
Other
763 stars 59 forks source link

Sigma Rules and Logging Made Easy #311

Open rgbrow1949 opened 4 weeks ago

rgbrow1949 commented 4 weeks ago

Sigma rules would be a valuable addition to Logging Made Easy enabling users to use them to detect attacks regardless of their platform but making it easy for users to use sigma rules requires us to give them easy-to-follow instructions and setting up and running sigma rules for themselves.

To do this, we will need to make new documentation with links and screenshots that describe the utility of sigma rules and how to use them.

Note: In a future version of LME, sigma rules could be a way to make LME platform-agnostic.