https://github.com/mthcht/threathunting-keywords-sigma-rules
Sigma detection rules for hunting with the threathunting-keywords project
https://github.com/mthcht/threathunting-keywords-sigma-rules
blueteam detection-engineering detection-rules dfir forensicartifacts mitre-attack siem sigma-rules threat-detection threat-hunting threathunting
Last synced: 10 months ago
JSON representation
Sigma detection rules for hunting with the threathunting-keywords project
- Host: GitHub
- URL: https://github.com/mthcht/threathunting-keywords-sigma-rules
- Owner: mthcht
- Created: 2023-08-02T09:22:58.000Z (almost 3 years ago)
- Default Branch: main
- Last Pushed: 2025-03-02T22:34:34.000Z (over 1 year ago)
- Last Synced: 2025-03-02T23:25:39.900Z (over 1 year ago)
- Topics: blueteam, detection-engineering, detection-rules, dfir, forensicartifacts, mitre-attack, siem, sigma-rules, threat-detection, threat-hunting, threathunting
- Language: Python
- Homepage:
- Size: 176 MB
- Stars: 54
- Watchers: 3
- Forks: 7
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- Funding: .github/FUNDING.yml
Awesome Lists containing this project
README
# ThreatHunting-Keywords-sigma-rules
Low quality sigma detections rules for hunting with Threat Hunting keywords from [ThreatHunting-Keywords](https://github.com/mthcht/ThreatHunting-Keywords)
You have the flexibility to regenerate all the rules using your own fields. This can be achieved by adjusting the field variables found in the script located here: https://github.com/mthcht/ThreatHunting-Keywords-sigma-rules/blob/main/_utils/create_sigma_rules.py
*Developed as an alternative solution for specific XDR/SIEM systems that exclusively operate with Sigma files, circumventing the limitations of not being able to use lookup tables*