Yamato-Security/hayabusa-rules
Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.
PythonNOASSERTION
Issues
- 0
Update rules to use `fieldref` instead of `equalsfield`, etc... [mid-late November]
#754 opened by YamatoSecurity - 0
Add AppLocker rules
#767 opened by YamatoSecurity - 0
- 1
Add correlation rules support tables to SupportedSigmaFieldModifiers.md
#750 opened by YamatoSecurity - 0
Add documentation on sigma correlations
#739 opened by YamatoSecurity - 0
- 0
Update supported modifiers table
#742 opened by YamatoSecurity - 1
Remove deprecated function usage
#653 opened by YamatoSecurity - 1
Update readme
#709 opened by YamatoSecurity - 1
regex directory removed
#730 opened by sdaaish - 0
Reduce the number of config files
#725 opened by YamatoSecurity - 3
Rule parse error(rules/windows/image_load/image_load_side_load_dbgmodel.yml)
#682 opened by fukusuket - 1
Update actions to use the separate converter
#673 opened by YamatoSecurity - 1
Duplicate keys in alias definitions
#649 opened by matthieugras - 0
Add Slack notification on GitHub Actions failure
#644 opened by fukusuket - 0
- 0
[bug] The order of the list of values in the `windash` modifier is different every time `logsource_mapping.py` is executed
#635 opened by fukusuket - 4
Create new UUIDv4 IDs for new rules created
#629 opened by YamatoSecurity - 0
[bug] logsource_mapping.py create a rule that Hayabusa does not support(`windash` modifier)
#622 opened by fukusuket - 0
[bug] `null` keywords do not get converted properly
#620 opened by fukusuket - 0
Incorrect Sysmon EID `14` default_details
#617 opened by fukusuket - 0
Incorrect Sysmon EID `13` default_details
#616 opened by fukusuket - 0
Add service and category for these rules
#615 opened by YamatoSecurity - 1
2.13.0: `tools/sigmac` unit tests are failing
#605 opened by sf-kastone - 4
Initial Running Syntax
#569 opened by computerclues - 1
`Possible Hidden Shellcode` rule's `json-timeline` does not convert `Details`
#598 opened by fukusuket - 4
Comments are erased when converting rules
#408 opened by YamatoSecurity - 13
Investigation about EventID in `Windows PowerShell.evtx` EventID:`400`/`600`/`800` ... etc
#512 opened by fukusuket - 1
Auto check for rule parsing errors
#520 opened by YamatoSecurity - 0
- 4
Incomplete field modifier(`expand`) rule created
#552 opened by fukusuket - 4
Incomplete field conversion in `registry_xx` rules
#476 opened by fukusuket - 1
- 1
- 3
Rules containing `look-around` regex will result in a parse error with Hayabusa
#517 opened by fukusuket - 5
Sigma repository's `PowerShell Classic(Windows PowerShell.evtx)` rules are undetectable with `Hayabusa`
#514 opened by fukusuket - 1
- 1
Add `sysmon` tag to sigma sysmon rules
#453 opened by YamatoSecurity - 7
- 6
- 0
- 2
[bug] `converter.py` does not convert rule correctly which has `contains` and `the last two character backslash`
#392 opened by fukusuket - 1
- 1
[bug] `converter.py` does not convert `aggregation condition` correctly which has replaced fields
#397 opened by fukusuket - 0
Update sysmon rule details fields
#402 opened by YamatoSecurity - 0
Self host log source mapping files
#380 opened by YamatoSecurity - 5
Need update sigmac toolpath in GitHub Actions
#357 opened by fukusuket - 3
- 0
Do not error on |cidr rules
#339 opened by YamatoSecurity - 5
Convert deprecated and unsupported rules
#327 opened by YamatoSecurity