Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reference to other rules in the condition of a detection #7

Open
thomaspatzke opened this issue Oct 16, 2022 Discussed in #6 · 1 comment
Open

Reference to other rules in the condition of a detection #7

thomaspatzke opened this issue Oct 16, 2022 Discussed in #6 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@thomaspatzke
Copy link
Member

Discussed in #6

Idea: add a correlation type that allows to inject/include detections from one rule to another and use them from there. This would be quite useful for false positive handling, generic rule parts and possibly other use cases typically encountered in integration of Sigma into an existing detection environment.

@thomaspatzke thomaspatzke added the enhancement New feature or request label Oct 16, 2022
@thomaspatzke thomaspatzke self-assigned this Oct 16, 2022
@rjurney
Copy link

rjurney commented Apr 1, 2023

This would form a graph - links between rules and the data types [and properties] within them - that would be useful for many reasons. This is something many companies working in cybersecurity are working on, it would make sense to pool resources.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants