Skip to content

Add Correlation Support#5759

Draft
nasbench wants to merge 2 commits intomasterfrom
add-correlations-support
Draft

Add Correlation Support#5759
nasbench wants to merge 2 commits intomasterfrom
add-correlations-support

Conversation

@nasbench
Copy link
Copy Markdown
Member

@nasbench nasbench commented Nov 17, 2025

Summary of the Pull Request

This PR adds correlation support to this repo. AKA once this is merged correlation rules will be supported and allowed to be merged in SigmaHQ rules repo.

This PR will start by migrating some correlations that were submitted in the past as well as establishing the necessary conventions and standard.

There is a corresponding validator PR SigmaHQ/pySigma-validators-sigmaHQ#60 that has to be merged.

As well as a new sigmahq-convention for correlations. SigmaHQ/sigma-specification#196

Below is a list of old PRs and rules that shoule be migrated / investigated as part of this initial MVP

We also have rules written in the old notation sitting in the unspported folder. Frack already did some initial work last year. See below:

Changelog

TBD

Example Log Event

N/A

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@nasbench nasbench added this to the Sigma-December-Release milestone Nov 17, 2025
@github-actions github-actions bot added the Review Needed The PR requires review label Nov 17, 2025
@nasbench nasbench added Work In Progress Some changes are needed and removed Review Needed The PR requires review labels Nov 17, 2025
@nasbench nasbench marked this pull request as ready for review November 17, 2025 00:35
@nasbench nasbench marked this pull request as draft November 17, 2025 00:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Work In Progress Some changes are needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant