Skip to content
This repository has been archived by the owner on Aug 5, 2024. It is now read-only.

Feature Request: Pass Yara Meta info to fieldnames/json #10

Open
ion-storm opened this issue Sep 19, 2019 · 2 comments
Open

Feature Request: Pass Yara Meta info to fieldnames/json #10

ion-storm opened this issue Sep 19, 2019 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@ion-storm
Copy link

ion-storm commented Sep 19, 2019

I'd like to be able to Tag Yara signatures with MITRE ATT&CK information, it would be awesome to be able to pass for instance the description field and meta tags to the json so I can add comma separated key value pairs to pass on to our SIEM for further enrichment/reporting and alerting.

@ion-storm
Copy link
Author

Example rule:
image

@FuzzySecurity
Copy link
Contributor

I think we can make that work. I'll put it on the books for the next update.

@FuzzySecurity FuzzySecurity self-assigned this Sep 20, 2019
@FuzzySecurity FuzzySecurity added the enhancement New feature or request label Sep 20, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants