Replies: 1 comment
-
Hi, hoping it will help you. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
SIGMA rules can also be written in OCSF keywords. If user wants to say write a SIGMA rule for AWS Cloudtrail data and using OCSF keywords (assuming original log records of Cloudtrail is converted into OCSF), how we can specify that this is SIGMA rule is using OCSF schema for a given log type. Secondly, user may need to add lot of Observables (or important keys) to be collected on such rule match to generate more contextualized findings. What are possible ways, we can specify such observables in SIGMA rule format.
Beta Was this translation helpful? Give feedback.
All reactions