Skip to content

Commit 9da3e92

Browse files
committed
new: [wazuh-rule] Wazuh-rule
1 parent 0d71e21 commit 9da3e92

1 file changed

Lines changed: 152 additions & 0 deletions

File tree

wazuh-rule/definition.json

Lines changed: 152 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,152 @@
1+
{
2+
"attributes": {
3+
"wazuh-rule": {
4+
"description": "Full Wazuh rule XML content.",
5+
"disable_correlation": true,
6+
"misp-attribute": "text",
7+
"ui-priority": 0
8+
},
9+
"rule-id": {
10+
"description": "Wazuh rule identifier from the rule id attribute.",
11+
"disable_correlation": true,
12+
"misp-attribute": "text",
13+
"ui-priority": 0
14+
},
15+
"level": {
16+
"description": "Wazuh alert level from the rule level attribute.",
17+
"disable_correlation": true,
18+
"misp-attribute": "text",
19+
"ui-priority": 0
20+
},
21+
"description": {
22+
"description": "Human-readable description of the rule.",
23+
"disable_correlation": true,
24+
"misp-attribute": "text",
25+
"ui-priority": 0
26+
},
27+
"group": {
28+
"description": "Wazuh group or groups associated with the rule.",
29+
"disable_correlation": true,
30+
"misp-attribute": "text",
31+
"multiple": true,
32+
"ui-priority": 0
33+
},
34+
"decoded_as": {
35+
"description": "Decoder name required for the rule to match.",
36+
"disable_correlation": true,
37+
"misp-attribute": "text",
38+
"ui-priority": 0
39+
},
40+
"if_sid": {
41+
"description": "Parent or prerequisite rule ID list.",
42+
"disable_correlation": true,
43+
"misp-attribute": "text",
44+
"multiple": true,
45+
"ui-priority": 0
46+
},
47+
"if_group": {
48+
"description": "Prerequisite group name.",
49+
"disable_correlation": true,
50+
"misp-attribute": "text",
51+
"multiple": true,
52+
"ui-priority": 0
53+
},
54+
"if_level": {
55+
"description": "Prerequisite alert level.",
56+
"disable_correlation": true,
57+
"misp-attribute": "text",
58+
"ui-priority": 0
59+
},
60+
"if_matched_sid": {
61+
"description": "Previously matched rule ID required within a time window.",
62+
"disable_correlation": true,
63+
"misp-attribute": "text",
64+
"multiple": true,
65+
"ui-priority": 0
66+
},
67+
"if_matched_group": {
68+
"description": "Previously matched group required within a time window.",
69+
"disable_correlation": true,
70+
"misp-attribute": "text",
71+
"multiple": true,
72+
"ui-priority": 0
73+
},
74+
"match": {
75+
"description": "Regular expression or string used to match log content.",
76+
"disable_correlation": true,
77+
"misp-attribute": "text",
78+
"multiple": true,
79+
"ui-priority": 0
80+
},
81+
"field": {
82+
"description": "Decoded field condition used by the rule.",
83+
"disable_correlation": true,
84+
"misp-attribute": "text",
85+
"multiple": true,
86+
"ui-priority": 0
87+
},
88+
"options": {
89+
"description": "Additional Wazuh rule options.",
90+
"disable_correlation": true,
91+
"misp-attribute": "text",
92+
"multiple": true,
93+
"ui-priority": 0
94+
},
95+
"frequency": {
96+
"description": "Number of times the rule must match before alerting.",
97+
"disable_correlation": true,
98+
"misp-attribute": "text",
99+
"ui-priority": 0
100+
},
101+
"timeframe": {
102+
"description": "Time window used with frequency-based matching.",
103+
"disable_correlation": true,
104+
"misp-attribute": "text",
105+
"ui-priority": 0
106+
},
107+
"ignore": {
108+
"description": "Time interval during which repeated alerts are ignored.",
109+
"disable_correlation": true,
110+
"misp-attribute": "text",
111+
"ui-priority": 0
112+
},
113+
"noalert": {
114+
"description": "Whether the rule suppresses alert generation.",
115+
"disable_correlation": true,
116+
"misp-attribute": "text",
117+
"ui-priority": 0
118+
},
119+
"mitre-id": {
120+
"description": "MITRE ATT&CK technique ID associated with the rule.",
121+
"disable_correlation": true,
122+
"misp-attribute": "text",
123+
"multiple": true,
124+
"ui-priority": 0
125+
},
126+
"reference": {
127+
"description": "Reference or origin of the Wazuh rule.",
128+
"misp-attribute": "link",
129+
"ui-priority": 0
130+
},
131+
"comment": {
132+
"description": "Comment or analyst note about the Wazuh rule.",
133+
"misp-attribute": "comment",
134+
"ui-priority": 0
135+
},
136+
"version": {
137+
"description": "Version of Wazuh or ruleset associated with the rule.",
138+
"disable_correlation": true,
139+
"misp-attribute": "text",
140+
"ui-priority": 0
141+
}
142+
},
143+
"description": "An object describing a Wazuh XML rule using common fields from the official Wazuh rule syntax.",
144+
"meta-category": "misc",
145+
"name": "wazuh-rule",
146+
"requiredOneOf": [
147+
"wazuh-rule",
148+
"rule-id"
149+
],
150+
"uuid": "5150952e-4a21-4011-aa20-204b6459e657",
151+
"version": 1
152+
}

0 commit comments

Comments
 (0)