diff --git a/Content/Content Packs/Windows TruKno Sigma Rules Content Pack.html b/Content/Content Packs/Windows TruKno Sigma Rules Content Pack.html new file mode 100644 index 0000000..619cfb8 --- /dev/null +++ b/Content/Content Packs/Windows TruKno Sigma Rules Content Pack.html @@ -0,0 +1,74 @@ + + +
The Windows Sigma Rules content pack is a collection of Sigma rules, selected from TruKno's Threat Detection Marketplace. The rules in this content pack are focused on Windows security threats. They are configured to work directly with existing Windows Illuminate content like Windows, Windows Security, Sysmon and PowerShell.
+When you enable this content pack, these rules appear on the Sigma Rules page
+
This technology pack uses the stream category:
+This content pack includes 77 Sigma rules.
+Critical threat level: 0 rule
+High threat level: 58 rules
+Medium threat level: 16 rules
+Low threat level: 3 rules
+Each rule includes remediation steps, which display if an alert is triggered based on the Sigma rule. See Apply Search Filters and Remediation Steps for details.
+When you enable this content, the new Sigma rules are added to the Sigma Rules page in Graylog. Follow the steps below to enable rules and configure alerts.
+Enable your chosen Sigma rules on the Sigma Rules page (Security > Sigma Rules).
+
+
To enable an inactive Sigma rule, click the toggle in the Enabled column.
+
+
Update rules if necessary. Some rules can result in many false positives and should be adjusted. Click the rule title to open the edit window where you can review the rule definition and other options. However, note that not all options are editable—including the rule definition.
+If you need to update the rule definition, first clone the rule (select Clone from the More menu). In the cloned rule, you can update any of the fields and options, including the rule definition.
+See Sigma Rules for complete information about creating and working with Sigma rules.
+Edit and update the event definition, if necessary. Each Sigma rule has a matching event definition, found on the Event Definitions tab of the Alerts page. For Sigma rules you enable, review the matching event definitions. You can add search filters or alerts as well as custom fields.
+
+
See Manage Illuminate Events for more information.
+