Rules #7
-
Where do I get the rules from, to avoid starting from scratch with my detection engineering? Is there a library I can start with: is Sigma ready to run for Marano? Is there something from marketplace like SOC Prime? I checked but seems not… |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Currently Matano does not ship with managed detections / ingest configuration for common log sources, but this is on our roadmap and will be prioritized in a few releases. Right now, you can follow the documentation to onboard a custom log source and write your first realtime detection using the Python detection-as-code format. |
Beta Was this translation helpful? Give feedback.
-
We just added a Matano backend for Sigma. This allows users to convert Sigma rules into Matano detections. Check out the docs here: https://www.matano.dev/docs/detections/importing-from-sigma-rules We will also work on integrating it into the sigma cli (pending upstream change) and add more Sigma pipelines. |
Beta Was this translation helpful? Give feedback.
We just added a Matano backend for Sigma. This allows users to convert Sigma rules into Matano detections. Check out the docs here: https://www.matano.dev/docs/detections/importing-from-sigma-rules
We will also work on integrating it into the sigma cli (pending upstream change) and add more Sigma pipelines.