Skip to content

Contribution to the "Projects that use or integrate Sigma rules" section #5758

@saerossec

Description

@saerossec

Hi,

I'd like to submit a project I'm working on. Saeros is a real-time HIDS based on Sigma rules focusing on Microsoft Active Directory and workstations. Its purpose is to detect suspicious activities including password-guessing attempts, data exfiltration, ...

As of today it relies on 2000+ Sigma rules and uses ETW for event subscription. It is relatively comparable to Chainsaw, SilkETW and Hayabusa.

Would it be possible to add it to the "Projects or Products that use or integrate Sigma rules" Readme section of the sigma project?

Many thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions