pySigma SigmaHQ validators
Project description
pySigma_validators_sigmaHQ
Purpose
Create all validators specific to the requirements of the SigmaHQ rules repository
Validators
Name | Description |
---|---|
sigmahq_date_existence | Checks if rule has a data. |
sigmahq_description_existence | Checks if rule has a description. |
sigmahq_description_length | Checks if rule has a description. |
sigmahq_falsepositives_banned_word | Checks if rule falsepositive start with a banned word. |
sigmahq_falsepositives_capital | Checks if rule falsepositive start with a capital. |
sigmahq_falsepositives_typo_word | Checks if rule falsepositive start with a common typo error. |
sigmahq_field_duplicate_value | Check uniques value in field list. |
sigmahq_fieldname_cast | Check field name have a cast error. |
sigmahq_filename | Check rule filename match SigmaHQ standard. |
sigmahq_filename_prefix | Check rule filename match SigmaHQ prefix standard. |
sigmahq_invalid_all_modifier | Check All modifier used with a single value. |
sigmahq_invalid_field_source | Check field Source use with Eventlog. |
sigmahq_invalid_fieldname | Check field name do not exist in the logsource. |
sigmahq_level_existence | Checks if rule has a level. |
sigmahq_link_description | Checks if rule description use a link instead of references. |
sigmahq_logsource_coherent | Checks if rule has Coherent logsource. |
sigmahq_logsource_known | Checks if rule has known logsource. |
sigmahq_space_fieldname | Check field name have a space. |
sigmahq_status_deprecated | Checks if rule has a status DEPRECATED. |
sigmahq_status_existence | Checks if rule has a status. |
sigmahq_status_unsupported | Checks if rule has a status UNSUPPORTED. |
sigmahq_title_case | Checks if rule title use capitalization. |
sigmahq_title_end | Checks if rule title end with a dot(.). |
sigmahq_title_length | Checks if rule has a title too long. |
sigmahq_title_start | Checks if rule title start with Detects. |
Data
All the data value are in the config.py
Maintainer
This pipelines is currently maintained by:
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Close
Hashes for pysigma_validators_sigmahq-0.5.2.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 4ec9ebc8aa3fb3a3593fce406a2ea41bdf389ee6dbfb13e5e98d28d6c9427963 |
|
MD5 | e83dbdb6c4af84dfadf6fd514fbb956e |
|
BLAKE2b-256 | 2470c759c0f3ca8faa7cc884f5fcc8bd3478e04906cb0064e6d04aef319e7829 |
Close
Hashes for pysigma_validators_sigmahq-0.5.2-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | b5b470b9e3278784af0c035786b0d96aa0a12f7f7ebf9376b0bcbd85e51d76f9 |
|
MD5 | 6520437c7398c714539d1ccd05530b2d |
|
BLAKE2b-256 | da1cc2dddd99a35e7edb107de24f16715f793ec9e48d2d0023d2ae2b83c4b53f |