Skip to content

Conversation

@Khadinxc
Copy link

I've made various additions to the project to improve it. This includes:

  • A more robust Python script for conversions with better error handling.
  • Utilising the newest Kusto backend from pySigma.
  • requirements.txt.
  • Inclusion of emerging-threats and threat-hunting rules rather then just the main rules repository.
  • Documentation on usage.

Khadinxc and others added 23 commits November 15, 2025 17:38
…n script for conversions with better error handling, utilising the newest KQL backend, requirements.txt. and much better documentation.
…ted the rules repo to match the current state of the helper script.
Spelling mistake on Sentinel
another spelling mistake
Update KQL Rules from Sigma Repository
…e SIGMA rules repo making it easier to follow the pattern established there instead of searching in tactics folders. Updated readme too.
Update KQL Rules from Sigma Repository:

Two New Rules
- HTML File Opened From Download Folder
- Github Self-Hosted Runner Execution
Three Rules Updated
- Suspicious Download via Certutil
- Suspicious File Downloaded from Direct IP via Certutil
- Suspicious File Downloaded from File Sharing Website via Certutil.
Update KQL Rules from Sigma Repository
Update KQL Rules from Sigma Repository
Update KQL Rules from Sigma Repository
Update KQL Rules from Sigma Repository
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant