Skip to content

Collection of Elastalert rules derived from Sigma, valid for ELK + Sysmon + Winlogbeat + Elastalert

Notifications You must be signed in to change notification settings

nicolagatta/ElastAlert_Sigma_Rules

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

21 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Sigma Rules for ELK + ElastAlert + Sysmon/Winlogbeat

A simple collection of Elastalert rules derived from Sigma

Valid for ELK + Sysmon + Winlogbeat + Filebeat + Elastalert

Derived from the great project @https://github.com/Neo23x0/sigma, along with some personal rules

Rules are configured to send alerts to an email alias named "elk-alert" (to be configured in your MTA)

About

Collection of Elastalert rules derived from Sigma, valid for ELK + Sysmon + Winlogbeat + Elastalert

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published