Skip to main content

panther-classic-converter

Tool for converting classic Panther detections into the Panther SDK format.

The converted rule serves as a good baseline and maintains existing functionality.

It is recommended that the generated filter be replaced with a composable list of filters to take advantage of the benefits of composable detections.

Installation

pip install panther-classic-converter

Usage

usage: panther_classic_converter [-h] [-a | --athena | --no-athena] [-o OUTPUT] filename

converts legacy detections to panther sdk detections

positional arguments:
  filename              YML filename to be converted

optional arguments:
  -h, --help            show this help message and exit
  -a, --athena, --no-athena
                        Datalake used by panther deployment. Used for scheduled queries.
  -o OUTPUT, --output OUTPUT
                        YML filename to be converted

Example

panther_classic_converter brute_force_by_ip.yml -o converted_brute_force_by_ip.py

Before

brute_force_by_ip.yml

brute_force_by_ip.py

After

converted_brute_force_by_ip.py

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

panther_classic_converter-0.1.0.tar.gz (8.6 kB view details)

Uploaded Source

File details

Details for the file panther_classic_converter-0.1.0.tar.gz.

File metadata

File hashes

Hashes for panther_classic_converter-0.1.0.tar.gz
Algorithm Hash digest
SHA256 1e89a1bbb4166987d0cd6fa4ed15c8615eb7f15bee488df92bacc441e9825e2b
MD5 e8b78d9a0e971829123bbfa12dd09ed6
BLAKE2b-256 48d252487af7f7bd09e19018695ce6e9e94578fb70fd02e047db88ad57a9d9e9

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

1 file

0.0.2

1 file

0.0.1

1 file

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page