Skip to content

no zeek/suricata target then why there are config files of suricata and zeek rule files in the directory? #2793

Closed Answered by frack113
IamTenacious asked this question in Q&A
Discussion options

You must be logged in to vote

Sigma is not designed to make zeek or suricata rules.
So there is no backend.

On the other hand there are rules on the alert logs of zeek or siricata.
Like the antivirus rules. The rule does not detect the virus but the alert message of the antivirus.
ala-suricata is for mapping the suricata alert log fields to Azure Log Analytics.
So you can make a rule like "if I see a alert.signature like 'RDP' in the surica alert then i wake up the SOC with a critical alert" 😃

I hope I made myself clear

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by frack113
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants