Please use this identifier to cite or link to this item: http://hdl.handle.net/10609/118327
Title: SigmaShooter: Aplicación web para la gestión y ejecución de firmas Sigma
Author: Llopis Polvoreda, José
Tutor: Mendoza Flores, Manuel Jesús
Abstract: Currently, most companies that use technology have security information and event management systems, known as SIEM. Relevant activities logs are sent and integrated to SIEM systems, where then can be correlate, manage and analyze to detect malicious activities or anomalous patterns. Each SIEM has its own language for querying data, so the same search can differ between different SIEM. This problem is solved with Sigma. Sigma is a generic and open signature format that allows you to describe relevant log events in a straight forward manner. The main goal of Sigma project is to provide a structured way in which researchers can describe their detection methods once developed and make them shareable with others. In this way, a Sigma signature created by an analyst can be converted to a query for most of used SIEM, although its procedure can be complicated and tedious if the number of rules is very high. To solve this problem, SigmaShooter project is presented in this Final Master's Project. SigmaShooter is a repository web application for Sigma rules administration, management and execution in a programmed and automatic way against the configured SIEM system. The final aim of the project is to provide a tool to help analysts run Sigma signatures easily, or even in an automatic way, against the organization's configured SIEM.
Keywords: SigmaShooter
SIEM
Sigma
Document type: info:eu-repo/semantics/masterThesis
Issue Date: 18-Apr-2020
Publication license: http://creativecommons.org/licenses/by-nc-nd/3.0/es/  
Appears in Collections:Trabajos finales de carrera, trabajos de investigación, etc.

Files in This Item:
File Description SizeFormat 
jollopolTFM0620memoria.pdfMemoria del TFM3,54 MBAdobe PDFThumbnail
View/Open