├── LICENSE.md ├── README.md ├── classes ├── AlertManager.py ├── DetectionRuleConverter.py ├── EMail.py ├── SummaryIndex.py ├── TriggeredAlert.py ├── UseCase.py └── __pycache__ │ ├── DetectionRuleConverter.cpython-37.pyc │ ├── EMail.cpython-37.pyc │ ├── SummaryIndex.cpython-37.pyc │ ├── TriggeredAlert.cpython-37.pyc │ └── UseCase.cpython-37.pyc ├── config └── config.yml ├── images ├── Sigma2SplunkAlert.jpg └── Sigma2SplunkAlert_Email.jpg ├── rules ├── lnx_shell_clear_cmd_history.yml └── sysmon_mimikatz_detection_lsass.yml ├── sigma2splunkalert ├── sigma2splunkalertRest ├── sigma_config └── splunk-all.yml └── templates └── template /LICENSE.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/LICENSE.md -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/README.md -------------------------------------------------------------------------------- /classes/AlertManager.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/AlertManager.py -------------------------------------------------------------------------------- /classes/DetectionRuleConverter.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/DetectionRuleConverter.py -------------------------------------------------------------------------------- /classes/EMail.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/EMail.py -------------------------------------------------------------------------------- /classes/SummaryIndex.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/SummaryIndex.py -------------------------------------------------------------------------------- /classes/TriggeredAlert.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/TriggeredAlert.py -------------------------------------------------------------------------------- /classes/UseCase.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/UseCase.py -------------------------------------------------------------------------------- /classes/__pycache__/DetectionRuleConverter.cpython-37.pyc: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/__pycache__/DetectionRuleConverter.cpython-37.pyc -------------------------------------------------------------------------------- /classes/__pycache__/EMail.cpython-37.pyc: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/__pycache__/EMail.cpython-37.pyc -------------------------------------------------------------------------------- /classes/__pycache__/SummaryIndex.cpython-37.pyc: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/__pycache__/SummaryIndex.cpython-37.pyc -------------------------------------------------------------------------------- /classes/__pycache__/TriggeredAlert.cpython-37.pyc: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/__pycache__/TriggeredAlert.cpython-37.pyc -------------------------------------------------------------------------------- /classes/__pycache__/UseCase.cpython-37.pyc: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/classes/__pycache__/UseCase.cpython-37.pyc -------------------------------------------------------------------------------- /config/config.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/config/config.yml -------------------------------------------------------------------------------- /images/Sigma2SplunkAlert.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/images/Sigma2SplunkAlert.jpg -------------------------------------------------------------------------------- /images/Sigma2SplunkAlert_Email.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/images/Sigma2SplunkAlert_Email.jpg -------------------------------------------------------------------------------- /rules/lnx_shell_clear_cmd_history.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/rules/lnx_shell_clear_cmd_history.yml -------------------------------------------------------------------------------- /rules/sysmon_mimikatz_detection_lsass.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/rules/sysmon_mimikatz_detection_lsass.yml -------------------------------------------------------------------------------- /sigma2splunkalert: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/sigma2splunkalert -------------------------------------------------------------------------------- /sigma2splunkalertRest: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/sigma2splunkalertRest -------------------------------------------------------------------------------- /sigma_config/splunk-all.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/sigma_config/splunk-all.yml -------------------------------------------------------------------------------- /templates/template: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zeflow/Sigma2SplunkAlert/HEAD/templates/template --------------------------------------------------------------------------------