Skip to content

Improve detection Sigma conversion evidence#2002

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/detection-sigma-conversion-fixtures-1797
Open

Improve detection Sigma conversion evidence#2002
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/detection-sigma-conversion-fixtures-1797

Conversation

@DENGXUELIN

Copy link
Copy Markdown

Summary

  • Adds backend conversion semantics evidence gates for Sigma-to-SIEM conversion.
  • Requires converter/backend version, exact command, generated query, warning output, field mapping, operator support, logic parity, manual edits, TP/TN execution, and performance evidence.
  • Adds vulnerable/benign fixtures for a converted query that misses a known-positive sample versus conversion parity with TP/TN evidence.

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence-balance check over changed .md files
  • Added-line ASCII check
  • Content marker check for DE-CONV-01, DE-CONV-08, Backend Conversion Semantics Evidence, fixture names, Known-positive, and Known-negative
  • Added-line secret-pattern scan
  • git merge-tree --write-tree origin/main HEAD -> 46c7aaac81cc4edc4b9f3dbf6756991e618b50fe

Closes #1797

Requested tier: Improver Moderate (USD 100)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] detection-engineering: add Sigma backend conversion evidence gates

1 participant