The structure of filters is as follows:
title description [optional] tags [optional] logsource category product [optional] definition [optional] detection {search-identifier} {List or object} ... condition level taxonomy
The following table outlines the components supported in the Trend Micro Sigma specification.
Component
|
Description
|
||
title |
The brief description of the filter (max. 256 characters)
|
||
description |
The detailed description of the filter (max. 1024 characters)
|
||
tags
|
The tags to categorize a filter
|
||
logsource |
The origin or type of data which the filter applies to
This section consists of three attributes:
|
||
category |
The type of data the filter queries
Supported values:
|
||
product |
The platforms from which the data originates
Supported values:
|
||
definition |
The specific subtype of data the filter queries
|
||
detection |
Consists of multiple
search-identifier elements and a condition elementA filter can have up to 19
search-identifier elements. |
||
The specific patterns to detect events
|
|||
condition |
The logical operators and symbols that define how Trend Vision One processes the
search-identifier elementsSupported operators:
|
||
level |
The severity associated with the event that this filter detects
Supported values:
|
||
taxonomy |
The taxonomy of the Sigma rule
|