Sigma rules not working #2052
-
Hi together, unfortunately I am not able to use the complete repository of SigmaHQ-rules. For example, every time I want to use the "Powershell" folder from the Windows rules, I get the following error in Timesketch after running Sigma Analyzer:
anyone had this error already and could fix it? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hey @feayeas as the error message expresses, the method used in a rule is not implemented in Timesketch (or more precise in Elastic). Besides, it is not recommended (and not supported) to just copy the whole Sigma project into your rule folder. It will break things and some rules will create false results. |
Beta Was this translation helpful? Give feedback.
Hey @feayeas as the error message expresses, the method used in a rule is not implemented in Timesketch (or more precise in Elastic).
Besides, it is not recommended (and not supported) to just copy the whole Sigma project into your rule folder. It will break things and some rules will create false results.
(e.g. #1532)