INNER CODE UNIT · Python
generate_sigma_rule
magicsword-io/LOLRMM · bin/generate_detections.py:50
def generate_sigma_rule():
"""Generate a generic Sigma rule for RMM detection"""
# Get a list of common RMM executables from YAML files
yaml_dir = os.path.join(
os.path.dirname(os.path.dirname(os.path.abspath(__file__))), "yaml"
)
yaml_files = glob.glob(os.path.join(yaml_dir, "*.y*ml"))
exe_list = []
for yaml_file in yaml_files:
try:
with open(yaml_file, "r", encoding="utf-8") as file:
data = yaml.safe_load(file)
if "Details" in data and "InstallationPaths" in data["Details"]:
# An empty "InstallationPaths:" key parses as None, which used to
# raise and skip the rest of the file.