INNER CODE UNIT · Python

generate_sigma_rule

magicsword-io/LOLRMM · bin/generate_detections.py:50

def generate_sigma_rule():
    """Generate a generic Sigma rule for RMM detection"""

    # Get a list of common RMM executables from YAML files
    yaml_dir = os.path.join(
        os.path.dirname(os.path.dirname(os.path.abspath(__file__))), "yaml"
    )
    yaml_files = glob.glob(os.path.join(yaml_dir, "*.y*ml"))

    exe_list = []
    for yaml_file in yaml_files:
        try:
            with open(yaml_file, "r", encoding="utf-8") as file:
                data = yaml.safe_load(file)

            if "Details" in data and "InstallationPaths" in data["Details"]:
                # An empty "InstallationPaths:" key parses as None, which used to
                # raise and skip the rest of the file.

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…