Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Corelight rules #132

Open
kris-watts-gravwell opened this issue Aug 23, 2023 · 2 comments
Open

Corelight rules #132

kris-watts-gravwell opened this issue Aug 23, 2023 · 2 comments
Assignees
Labels
03 - Low low priority 06 - enhancement improvement or extension of existing feature

Comments

@kris-watts-gravwell
Copy link
Contributor

Corelight publishes a bunch of rules/alerts for elastic:
https://github.com/corelight/Elasticsearch_rules/blob/main/Elastic%20SIEM%20Rules/Elastic_Corelight_rules.ndjson

We can adapt these into the corelight kit pretty easily

@kris-watts-gravwell kris-watts-gravwell added 06 - enhancement improvement or extension of existing feature 03 - Low low priority labels Aug 23, 2023
@kris-watts-gravwell
Copy link
Contributor Author

also here are phantom playbooks for corelight: https://github.com/corelight/phantom-playbooks

@kris-watts-gravwell
Copy link
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
03 - Low low priority 06 - enhancement improvement or extension of existing feature
Projects
None yet
Development

No branches or pull requests

3 participants