Sigma rules on Jupyter Notebooks
Date Issued
October 7, 2024
Type
Πτυχιακή Εργασία
Abstract
This thesis is based on one of the most popular branches of IT, cyber
security. As the digital landscape has developed to a high level, the threats
are increasing. Cybersecurity is the protection of devices and services
connected to the internet from so-called hackers. Employing strong
cybersecurity measures preserves information privacy and trust in digital
systems. The use of various technologies and methods protects against
cyber attacks. Many different areas need protection, such as applications
and mobile devices on networks. There are not a few times that we have
seen many large companies have been attacked, which have caused
significant damage both to the records and to the credibility of these
companies. Also, the problems can be caused not only by external factors,
but also by internal ones. of an organization, for this reason staff training
with security rules is essential. Thus, data security, system integrity and
user privacy protection is a key part in the digital space.
In particular, in the following work I dealt with writing Sigma Rules in
Jupyter Notebooks, which significantly affect SIEM systems and more
specifically Wazuh. The purpose of using Sigma rules in SIEM systems is
to improve their ability to detect and manage threats. SIEM systems collect
and analyze log data from various sources within an organization to detect
anomalies and potential threats. Sigma Rules, written in YAML, describe
patterns of malicious activity and can be converted into formats that SIEM
systems understand. In this way, Sigma rules can be integrated into SIEM
tools to enhance threat detection and response, allowing SIEMs to more
effectively detect suspicious events and alert security managers.
Additionally, the flexibility and adaptability of Sigma Rules allows
organizations to update and expand their rules, ensuring protection against
new and evolving threats.
Subjects
