INNER CODE UNIT · Python

generate_indexes

panther-labs/panther-analysis · .scripts/generate_indexes.py:19

def generate_indexes(directory):
    """
    Generates JSON and Markdown indexes, directory points to the root directory of the repo
    """

    detections = {}
    query_lookup = {}  # Maps QueryNames to their YAML
    logtype_lookup = {
        # Maps tableified names for all LogTypes e.g. onepassword_signinattempt => OnePassword.SignInAttempt this is used to extract "Log Types" from queries
        'crowdstrike_aidmaster': 'Crowdstrike.AIDMaster',
        'snowflake.account_usage': 'Snowflake.AccountUsage'
    }

    for root, subdirectories, files in os.walk(directory):
        for file in files:
            if '/rules' in root or '/policies' in root or '/queries' in root or '/simple_rules' in root or '/correlation_rules' in root:
                if file[-4:] == '.yml':
                    yaml_path = os.path.join(root, file)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…