Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sigma date format different than ISO 8601 #32

Closed
wikijm opened this issue Oct 6, 2024 · 2 comments
Closed

Sigma date format different than ISO 8601 #32

wikijm opened this issue Oct 6, 2024 · 2 comments

Comments

@wikijm
Copy link
Contributor

wikijm commented Oct 6, 2024

Hi everyone!

According to the Sigma Rules Specification, the date format in Sigma rule files must follow the ISO 8601 standard, using the separator format (YYYY-MM-DD instead of YYYY/MM/DD).

I’ve made a change in the main...wikijm:LOLRMM:patch-1 branch, but I’m not entirely sure if I modified the correct part of the code. Additionally, I’m uncertain if this change might affect other mechanisms in your GitHub repository or on the lolrmm.io website.

The reason for this change is that when I try to transform, with that repo, your Sigma rules to SentinelOne Power Query using sigma-cli through GitHub Actions, I encounter the following error message: “Error occurred while processing […]_sigma.yml: Rule date ‘YYYY/MM/DD’ is invalid, must be yyyy-mm-dd”:
image

If this request makes sense, I can create a pull request accordingly.

Thank you for this project; I’m happy to use it for Threat Hunting! 😃

@nasbench
Copy link
Member

nasbench commented Oct 6, 2024

Hi @wikijm

Thanks for this issue, and yes, you can open a PR with your fix its fine.

Just FYI I already have some tuning to the sigma gen script that i'm gonna push to fix some other issues.

@wikijm
Copy link
Contributor Author

wikijm commented Oct 6, 2024

Hi @nasbench,

Wonderful, thanks a lot!
Closing this ticket as #34 was created.

Have a nice sunday.

@wikijm wikijm closed this as completed Oct 6, 2024
wikijm added a commit to wikijm/LOLRMM that referenced this issue Nov 14, 2024
magicsword-io#32

According to the Sigma Rules Specification, the date format in Sigma rule files must follow the ISO 8601 standard, using the separator format (YYYY-MM-DD instead of YYYY/MM/DD).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants