├── .gitignore ├── LICENSE ├── README.md ├── pyproject.toml ├── requirements.txt ├── setup.cfg ├── setup.py ├── src └── sigmatau │ ├── __init__.py │ ├── main.py │ └── schemas.py └── tests ├── basic_test.py ├── rules ├── sigma │ ├── file_event_lnx_persistence_sudoers_files.yml │ ├── net_connection_lnx_ngrok_tunnel.yml │ ├── proc_creation_win_7zip_cve_2022_29072.yml │ ├── web_cve_2019_11510_pulsesecure_exploit.yml │ ├── win_alert_mimikatz_keywords.yml │ └── win_exchange_set_oabvirtualdirectory_externalurl.yml └── tau │ └── win_alert_mimikatz_keywords.yml ├── sigma_test.py └── tau_test.py /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/.gitignore -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/README.md -------------------------------------------------------------------------------- /pyproject.toml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/pyproject.toml -------------------------------------------------------------------------------- /requirements.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/requirements.txt -------------------------------------------------------------------------------- /setup.cfg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/setup.cfg -------------------------------------------------------------------------------- /setup.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/setup.py -------------------------------------------------------------------------------- /src/sigmatau/__init__.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/src/sigmatau/__init__.py -------------------------------------------------------------------------------- /src/sigmatau/main.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/src/sigmatau/main.py -------------------------------------------------------------------------------- /src/sigmatau/schemas.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/src/sigmatau/schemas.py -------------------------------------------------------------------------------- /tests/basic_test.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/basic_test.py -------------------------------------------------------------------------------- /tests/rules/sigma/file_event_lnx_persistence_sudoers_files.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/sigma/file_event_lnx_persistence_sudoers_files.yml -------------------------------------------------------------------------------- /tests/rules/sigma/net_connection_lnx_ngrok_tunnel.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/sigma/net_connection_lnx_ngrok_tunnel.yml -------------------------------------------------------------------------------- /tests/rules/sigma/proc_creation_win_7zip_cve_2022_29072.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/sigma/proc_creation_win_7zip_cve_2022_29072.yml -------------------------------------------------------------------------------- /tests/rules/sigma/web_cve_2019_11510_pulsesecure_exploit.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/sigma/web_cve_2019_11510_pulsesecure_exploit.yml -------------------------------------------------------------------------------- /tests/rules/sigma/win_alert_mimikatz_keywords.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/sigma/win_alert_mimikatz_keywords.yml -------------------------------------------------------------------------------- /tests/rules/sigma/win_exchange_set_oabvirtualdirectory_externalurl.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/sigma/win_exchange_set_oabvirtualdirectory_externalurl.yml -------------------------------------------------------------------------------- /tests/rules/tau/win_alert_mimikatz_keywords.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/rules/tau/win_alert_mimikatz_keywords.yml -------------------------------------------------------------------------------- /tests/sigma_test.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/sigma_test.py -------------------------------------------------------------------------------- /tests/tau_test.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/priamai/sigmatau/HEAD/tests/tau_test.py --------------------------------------------------------------------------------