Incorrect Sigma Rule to EQL Conversion in Security Onion - Incorret conversion of CommandLine|contains|windash: ' -s' #13308
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM32 Storage for /250GB Storage for /nsm1TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailThere is a problem in the translation of the sigma rules in EQL, SO correctly translates for example
is translated in
and not
Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
I reported this bug to the Sigma project last month - they fixed it (SigmaHQ/pySigma-backend-elasticsearch@24fe2c5) and the fix made it into 2.4.80. |
Beta Was this translation helpful? Give feedback.
I reported this bug to the Sigma project last month - they fixed it (SigmaHQ/pySigma-backend-elasticsearch@24fe2c5) and the fix made it into 2.4.80.