Skip to content
Discussion options

You must be logged in to vote

Just found this discussion and moved it to the Elastic repository. In the meanwhile the backend supports ES|QL with Sigma correlation rules, which enables further detection possibilities. Nevertheless, the goal of Sigma is not to support every feature of all SIEMs. E.g. new terms rules are not supported and generally I don't see much value in implementing indicator matching as Sigma rule. This should be considered in a detection as code pipeline, e.g. as stated by @jabrcks by adding custom extensions to Sigma rules that enable to create custom queries for cases where Sigma is not sufficient.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by thomaspatzke
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants