Thomas Patzke Profile
Thomas Patzke

@blubbfiction

Followers
5K
Following
2K
Media
161
Statuses
7K

Incident Response, Threat Hunting. Opensource security tool developer (https://t.co/2twMtVpZtL). Moved to @[email protected]

Germany
Joined October 2009
Don't wanna be here? Send us removal request.
@DefensiveDepth
Josh Brower
2 years
Check out my newly updated @sigma_hq course - Refreshed content to include all the great changes happening with the Sigma project! https://t.co/ijM4f0w31e #DetectionEngineering #InfoSec #SIGMA
Tweet card summary image
networkdefense.co
@NetworkDefense
Applied Network Defense
2 years
We've recently deployed some major updates to our @sigma_hq class. To celebrate, you can sign up for $50 off through Friday using code SIGMAV2 Some updates include: - Using Sigma rule packages to customize your detection coverage 1/3
0
6
32
@nas_bench
Nasreddine Bencherchali
2 years
2023 has been a very busy year for the @sigma_hq team and a great year for the Sigma community at large. We've seen a greater adoption of Sigma across all of the community and even from big vendors ranging from Qradar native support for Sigma rules, Splunk leveraging Sigma for
4
22
96
@nas_bench
Nasreddine Bencherchali
2 years
A new update has just dropped to the VsCode @sigma_hq extension πŸš€. My colleague @_humpalum graciously integrated sigconverter directly into the extension via the APIπŸ§™β€β™‚οΈ In addition to all the autocomplete features and the goodness that the extension offers for sigma rule
2
28
67
@nas_bench
Nasreddine Bencherchali
2 years
[PySigma Basics Tips 🌟] If you leverage Sigma rules, you're probably aware that fields are vendor agnostic. Which means we can map them to anything we need. One of the feature that pySigma offers is transformations Say you normalize command line field to something like cli.
2
6
21
@nas_bench
Nasreddine Bencherchali
2 years
.@m3nixx and I took some time this weekend to cook something cool for Sigconverter https://t.co/BF2ssNHaj0 πŸ§‘β€πŸ³ You can now apply custom pySigma processing pipelines directly on the website. You might ask what does this mean? Custom processing pipelines allows you to transform a
3
24
67
@andriinb
Andrii Bezverkhyi
2 years
We have just open sourced https://t.co/efwkFtbiWA and brought it back to original https://t.co/QelW1nyVxA Thank you everyone for your tremendous support from 2018 until today and into the future! 🧬 Supported Language Formats RootA and Sigma Rules can be translated into the
uncoder.io
Free online detection engineering IDE and translation engine for Roota & Sigma rules.
@Uncoder_IO
uncoder_io
2 years
I am https://t.co/lLbE2HEE4W and here is my source code: https://t.co/gXKnlDG3r4 status: public beta I support translation of #IOC packages, #sigma and #rootA rules to specific SIEM languages, autocomplete with @MITREattack 14.0, #OCSF and Sigma taxonomy
4
35
86
@4ndur1n
Andurin
2 years
Elasticsearch keyword searches are fast and fine but misses case-insensitive searches. Event-Query-Language (EQL) sounds like a valuable answer for many security related use cases. Today I'm allowed to release pySigma-backend-elasticsearch (v1.0.8 ) with a EQL Support. @sigma_hq
1
10
39
@blubbfiction
Thomas Patzke
2 years
New blog post about the the Sigma converter feature that allows to create custom output formats just by writing some YAML definition and templates: Introducing Query Post-Processing and Output Finalization to Processing Pipelines https://t.co/J4ch6DoS3N
0
24
76
@nas_bench
Nasreddine Bencherchali
2 years
PySigma templating feature is a game changer for backends output! A blog describing the feature is coming soon by @blubbfiction on @sigma_hq medium. Follow it here
0
7
47
@frack113
frack113
2 years
Hi everyone, to get the weekend well started an Elastalert working conversion thanks to the template ouput in the latest version of #PySygma. I even did a #SIGMA level to priority conversion in the template. It's time to stop using sigmac πŸ˜† @sigma_hq
0
5
16
@_josehelps
Jose Enrique Hernandez
2 years
πŸŽ‰ Introducing SigConverter! πŸŽ‰ We're thrilled to announce the launch of https://t.co/37dKqyAMN3, a respectful-of-privacy and community-driven tool designed to simplify and streamline your Sigma rule conversion process. πŸ› οΈ 🌟 Why SigConverter? πŸ€– Easily convert to your SIEM of
7
85
202
@alexanderjaeger
Alex
2 years
πŸ•ΆοΈπŸ§πŸ‘€πŸ₯·πŸ₯A new project by the Security Response team of @Google: https://t.co/fTO9MvhPBa. It fills a gap I have seen for years, asking the same questions in similar investigations across analysts who might have different background and know how. πŸ•ΆοΈπŸ§πŸ‘€πŸ₯·πŸ₯
5
91
285
@blubbfiction
Thomas Patzke
2 years
This will be integrated into the next version of Sigma CLI. I also plan a blog post about it in our Medium publication: https://t.co/9WFxrO09x4 4/4
0
0
0
@blubbfiction
Thomas Patzke
2 years
It also allows to put further query parts before and after the generated query, which was requested several times. Further use cases could be direct ingestion of generated queries into the SIEM directly from the conversion process and surely much more. 3/4
1
0
1
@blubbfiction
Thomas Patzke
2 years
In the new release processing pipelines were extended by query post-processing and output finalization. This allows to create custom output formats out of queries generated by backends by embedding them into templates (Jinja2 is supported!). 2/4
1
0
0
@blubbfiction
Thomas Patzke
2 years
Just released pySigma 0.10: https://t.co/jwHlxkQAIz It contains lots of extensions and fixes provided by the steadily growing community of pySigma contributors! Thanks to everyone of you! 1/4🧡
Tweet card summary image
github.com
Added Extended processing pipelines by query post-processing and output finalization. ⚠️ Breaking Changes ⚠️ The order of ProcessingPipeline parameters has changed. New elements postprocessing_i...
1
20
46
@blubbfiction
Thomas Patzke
2 years
New blog post: Connecting Sigma Rule Sets to your Environment with Processing Pipelines https://t.co/fF4IlvuHZw If you convert Sigma rules into queries you should read this, especially if you never heard about processing pipelines before.
0
19
28
@blubbfiction
Thomas Patzke
2 years
Just published my first post in the Sigma blog: Building Flexible & Reusable Detections with Sigma Placeholders https://t.co/Gsw27OPw4X
0
14
35
@frack113
frack113
3 years
Hi, I've started a small project to help choose logsources #sigma with simple questions here https://t.co/HMDnapDLUh. Any help or ideas are welcome. You can make a GUI , fix my code (No worry, I know it's dirty )... But If anyone can turn it into a Visual Novel Game😏
Tweet card summary image
github.com
Small questions to help select the right logsource for effective detection - frack113/sigma_logsource_helper
0
7
14