google / timesketch

Collaborative forensic timeline analysis
Apache License 2.0
2.58k stars 589 forks source link

Deprecate Sigma status CSV usage from code #2913

Closed jaegeral closed 1 year ago

jaegeral commented 1 year ago

Removing some left overs from the old File based Sigma usage.

As the sigma rule status csv is not maintained, it is removed

If there is a new need / desire to track status of upstream Sigma rules and which work in Timesketch / which not, a new way needs to be established, a CSV does not play nice with the community.

berggren commented 1 year ago

If the CSV file has been deprecated can you add a note in it that says so? Then we can mark it for deletion in a couple of months.

jaegeral commented 1 year ago

If the CSV file has been deprecated can you add a note in it that says so? Then we can mark it for deletion in a couple of months.

clarified in the PR description, the usage of the file has been deprecated, the content of the file itself might still be valuable for me / others, thus moving it to contrib outside of the data folder, as the file itself is no longer used in the code.