No description
- Fixed fields regex to also look for '==' operators - Fixed fields regex to avoid misinterpreting Windows drive letters as fields - Added log source regex to extract from queries - Split rows so there is only one T-code for each row - Map sub-T-codes to ATT&CK data source and component rather than only T-code if available - Minor tweaks |
||
|---|---|---|
| edr2df | ||
| thirdparty | ||
| .gitignore | ||
| .gitmodules | ||
| edr2df.ipynb | ||
| README.md | ||
edr2df
edr2df (Elastic Detection Rules to Dataframes) converts Elastic Co's detection rules to Pandas dataframes.