Skip to main content

pySigma Tracee processing pipelines

Project description

pySigma-backend-tracee

This backend utilizes Sigma rules to configure the Tracee to apply Sigma rules to containerized environments via eBPF.

Conversion procedure

  1. Choose SigmaRules (Filter by Logsource)
  2. Tranlate to GO Signature
  3. Build Tracee with Custom Signatures
  4. Package to a container
  5. Deploy to machine

Deployment

Tracee is deployed by an Kubernetes Deamon Set. Every Node runs a Instance of Tracee.

Log Collection

Logs

Performance Metrics can be visualized by Prometheus and Grafana

  • Implement for Evaluation

Output is send to Fluentbit

Fluentbit sends the information to Elasticsearch?

Project details


Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page