New target Qradar Extension Rules #45
Closed
nNipsx-Sec
started this conversation in
Ideas
Replies: 2 comments 2 replies
-
Generally all backends for pySigma for target languages are welcome 😊 There's already a QRadar backend for the legacy sigmatools which could be used as base for a pySigma backend. I'm currently working on a backend template (cookiecutter) that could be helpful to start a new pySigma backend. |
Beta Was this translation helpful? Give feedback.
2 replies
-
QRadar-AQL - https://github.com/IBM/pySigma-backend-QRadar-AQL |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have idea for Qradar extension rules.
The Extension rules of Qradar in zip file with xml format, so i think we can create new target for Qradar extension with this
=> Easier for generate sigma rules and deployment rules in Qradar SIEM
Beta Was this translation helpful? Give feedback.
All reactions