github SigmaHQ/sigma 0.14
Sigma Release 0.14

latest releases: r2024-05-13, r2024-04-29, r2024-03-26...
4 years ago

Added

  • sigma-similarity tool
  • LimaCharlie backend
  • Default configurations for some backends that are used if no configuration is passed
  • Regular expression support for es-dsl backend (propagates to backends derived from this like elastalert-dsl)
  • Value modifiers:
    • startswith
    • endswith

Changed

  • Removal of line breaks in elastalert output
  • Searches not bound to fields are restricted to keyword fields in es-qs backend
  • Graylog backend now based on es-qs backend

Fixed

  • Removed ProcessCommandLine mapping for Windows Security EventID 4688 in generic
    process creation log source configuration

Don't miss a new sigma release

NewReleases is sending notifications on new releases.