sanwieb / sigwah Goto Github PK
View Code? Open in Web Editor NEWA Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset
License: GNU General Public License v3.0
A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset
License: GNU General Public License v3.0
Hi,
I really like your work on this and have already started putting it to fruitful use. I did find that when I bolt these rules onto the stock Wazuh ruleset, that the internal rule count sky rockets to over 200,000 rules, about 50 times bigger than normal. This pushes Wazuh's memory requirements for analysisd (which loads the ruleset) up to over 2GB and makes ruleset load time go from very quick to around 10 seconds, delaying ossec-logtest and wazuh-manager service restarts. Other than the memory demands and the slow ruleset loading, it seems to be working fine. I was discussing this with Wazuh's head developer this morning and he discourages heavy use of <if_group> because
<if_group> is a shortcut to create N rules with <if_sid> for each existing rule belonging that group.
This issue is amplified with <if_group>windows</if_group> specifically because there are so very many rules in the windows group. It would be ideal if these Sigma-related Wazuh rules could be hung off of the specific Wazuh parent rules relevant to them using the <if_sid> construct instead of <if_group> but that may make automatic generation of Wazuh rules based off of the Sigma ruleset much more difficult. Still, it would give vastly more than an order of magnitude analysisd memory reduction and Wazuh ruleset load speed.
What do you think?
Kevin
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.