Skip to content

Latest commit

 

History

History
26 lines (15 loc) · 1018 Bytes

README.md

File metadata and controls

26 lines (15 loc) · 1018 Bytes

Security Onion - Resources

This repository contains the following resources:

Security Onion specific Sigma Rules

This Sigma ruleset is maintained by Security Onion and is loaded by default into the Security Onion Detections module.

Event Filters

  • Location: main branch, event_filters folder
  • License: MIT

Generic event filters for process_creation, dns_query, file_create and more. Used by Security Onion to generate event filters for Elastic Defend events.

Originally sourced from https://github.com/Neo23x0/sysmon-config and https://github.com/olafhartong/sysmon-modular

AI-Generated Detection Summaries

Summaries created by an LLM for Suricata, Sigma and YARA rules. Used by Security Onion in the Detections module.