The number of artifacts in the exchange is growing and we need to trim them a bit in order to increase quality.
The following guidelines make sense
- Artifacts the specifically search in event logs should be merged into the sigma project
- Artifacts the look in sqlite files should be merged in sqlitehunter
- Artifacts that run external tools should pin tool hashes
- Artifacts that look for specific threats should be removed once the threat is too old (e.g. log4j)