Sigma base fields that work for all vendors #2552
-
Hello all First of all, thanks for this great library I really appreciate the great work. I am trying to write Sigma rules/queries that when translated, will automatically work for major SIEMs. I can't find the core Sigma fields that would be mapped to corresponding fields for all vendors. For exmaple:
Is there not suppose to be a closed set of fields for Sigma queries for such things ? Maybe I have mistaken the whole structure and would be happy if anyone can assist. Thank you all |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hi, Rule should use the original field name. For windows is easy : Event Viewer select Details and Xml. In any case DO NOT use ECS , Splunk or SIEM custom field name. Not all the backend mapping files are up to date, some old field name may still be in it but not by the rules anymore... |
Beta Was this translation helpful? Give feedback.
Hi,
Rule should use the original field name.
The space in field nane are replace by
_
For windows is easy : Event Viewer select Details and Xml.
For BIND need to works with the rfc 😄
In any case DO NOT use ECS , Splunk or SIEM custom field name.
Not all the backend mapping files are up to date, some old field name may still be in it but not by the rules anymore...
Hope to be usefull