Generate event rule documentation
This commit is contained in:
parent
e43d7689a0
commit
7f4d5b42fd
8 changed files with 378 additions and 5 deletions
|
|
@ -160,7 +160,7 @@ turning Sentinel into a noisy rules dump.
|
|||
configured rules.
|
||||
- ✅ Add `enodia-sentinel rules test <event-json>` so operators can validate
|
||||
custom event rules against captured or fixture events.
|
||||
- Generate rule documentation from source defaults: SID, signature, classtype,
|
||||
- ✅ Generate rule documentation from source defaults: SID, signature, classtype,
|
||||
event type, match fields, expected false positives, and drill coverage.
|
||||
- Require a fixture or safe red-team drill for every built-in SID, including
|
||||
event-only and correlation SIDs.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue