Skip to content

Releases: SigmaHQ/pySigma

pySigma 0.6.7

21 Jul 00:28
Compare
Choose a tag to compare

Fixed: or-linking of multi-field mappings.

pySigma 0.6.6

20 Jul 00:33
Compare
Choose a tag to compare
  • Added templating to add_condition transformation.
  • Added further default Windows log sources.

pySigma 0.6.5

08 Jul 22:27
Compare
Choose a tag to compare

Added Sigma Windows service identifiers to Windows event log channel name mapping.

pySigma 0.6.4

27 Jun 22:17
Compare
Choose a tag to compare

Added escaping of field names.

pySigma 0.6.3

21 Jun 22:10
Compare
Choose a tag to compare
  • Bugfix in conversion of Sigma rules into a dict with numeric values.
  • Specific error on tags without namespace.

v0.6.2

28 May 22:47
Compare
Choose a tag to compare
  • Quoting of field names.
  • Fixed handling of query expressions.

pySigma 0.6.1

26 May 22:20
Compare
Choose a tag to compare

Fixed handling of empty detections caused by drop detection item transformation.

pySigma 0.6.0

03 May 23:01
Compare
Choose a tag to compare
  • Startswith, endswith, contains and dedicated wildcard match expressions
  • Backend output format specific processing pipelines
  • New modifier 'windash'
  • Fixed precedence of expanding value modifier results
  • Processing pipeline state
  • SetState transformation

pySigma 0.5.2

28 Apr 20:46
Compare
Choose a tag to compare

Bugfix (unnecessary attr import)

pySigma 0.5.1

16 Apr 22:14
Compare
Choose a tag to compare
  • Additional common log source definitions (moved from Splunk backend)