[ English ] | [日本語]
This repository hosts the sigma detection rules for Suzaku.
Upstream Sigma rules are automatically updated daily and placed in the sigma
directory.
Built-in rules for Suzaku are placed in the suzaku
directory.
If you notice any problems with the upstream Sigma rules, please create an issue in the sigma repository.
If you notice any problems with Suzaku's sigma rules, please create an issue here.
- Suzaku: Our DFIR analysis tool for cloud logs.
- suzaku-sample-data: Sample datasets with attack data for creating detection rules.