Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR adds mitre d3fend tag namespace.
See SigmaHQ/sigma-specification#147 for the specification definition.
It also fixes a typo in ATT&CK function where in the allowed tags combined dict, the full dict was merged instead of only the keys of both
mitre_attack_intrusion_sets
andmitre_attack_software
TODO
Wait for update tags appendix - Add D3FEND tag namespace sigma-specification#147 before merging thisNote: For now I generated the d3fend data manually with an ad-hoc script. In the future i'll add a script to the tools folder to automate updates.