Skip to content

Opening book details…

Can I read Sigma Rules for Threat Detection on EtoBox?

Sigma Rules for Threat Detection by u__q is a document available to read on EtoBox.

What is Sigma Rules for Threat Detection about?

The document discusses threat hunting using application logs and log signatures. It introduces Sigma, an open source format for log signatures. Sigma rules are written in YAML and include a scope definition, search identifiers to identify log events, and a condition to correlate events. Problems with existing approaches are a lack of standard format, different SIEM products covering different signatures, and vendor lock-in. Sigma aims to address these with a generic signature format, open repository of rule

Author
u__q
Language
EN