Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Panda-PAPS new decoders and rules #437

Merged
merged 2 commits into from
Aug 27, 2019
Merged

Panda-PAPS new decoders and rules #437

merged 2 commits into from
Aug 27, 2019

Conversation

jmmallorq
Copy link
Contributor

Hello,

I created new Decoders and Rules for Panda Advanced Protection Service (PAPS) Windows application.

We used Sibling Decoders to extract all of the dynamic fields from every log event.

For the Rules, I used both <match> and <field name=""> conditions to generate the corresponding alerts. I assigned IDs from 64200 to 64208.

The script output doesn't show any "Failed" message:

# ./runtest.py
- [ File = ./tests/panda_paps.ini ] ---------
........

I upload the following files:

  • decoders/0206-panda-paps_decoders.xml
  • rules/0675-panda-paps_rules.xml
  • tools/rules-testing/panda_paps.ini

Regards,
J. M. Mallorquín

@elwali10
Copy link
Member

Hello @jmmallorq,

Thanks for your contribution.

I have slightly modified the decoder naming to respect the numeric order and avoid any confusion.

Best regards,
Wali

@snaow snaow merged commit d3547b0 into master Aug 27, 2019
@snaow snaow deleted the jmmallorquin-paps branch August 27, 2019 06:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants