Skip to content

Audit artifact exchange to remove older artifacts #766

@scudette

Description

@scudette

The number of artifacts in the exchange is growing and we need to trim them a bit in order to increase quality.

The following guidelines make sense

  1. Artifacts the specifically search in event logs should be merged into the sigma project
  2. Artifacts the look in sqlite files should be merged in sqlitehunter
  3. Artifacts that run external tools should pin tool hashes
  4. Artifacts that look for specific threats should be removed once the threat is too old (e.g. log4j)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions