You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When creating a Sigma rule that is intended to be largely (but not always) used with a correlation rule or could be used with multiple different correlation rules, there does not seem to be a good way of indicating that in the Sigma rule metadata itself.
The related field allows us to associate Sigma rules together, but the types available do not seem (to me) to align with the above desired use-case - my suggestion is to introduce a type: correlation or type: recommended_correlation to the standard to enable it.
A simple example usage might look like the following Sigma rule:
When creating a Sigma rule that is intended to be largely (but not always) used with a correlation rule or could be used with multiple different correlation rules, there does not seem to be a good way of indicating that in the Sigma rule metadata itself.
The
related
field allows us to associate Sigma rules together, but thetype
s available do not seem (to me) to align with the above desired use-case - my suggestion is to introduce atype: correlation
ortype: recommended_correlation
to the standard to enable it.A simple example usage might look like the following Sigma rule:
With the associated Sigma correlation rule:
The text was updated successfully, but these errors were encountered: