pySigma Tracee processing pipelines
Project description
pySigma-backend-tracee
This backend utilizes Sigma rules to configure the Tracee to apply Sigma rules to containerized environments via eBPF.
Conversion procedure
- Choose SigmaRules (Filter by Logsource)
- Tranlate to GO Signature
- Build Tracee with Custom Signatures
- Package to a container
- Deploy to machine
Deployment
Tracee is deployed by an Kubernetes Deamon Set. Every Node runs a Instance of Tracee.
Log Collection
Logs
Performance Metrics can be visualized by Prometheus and Grafana
- Implement for Evaluation
Output is send to Fluentbit
Fluentbit sends the information to Elasticsearch?