Aristotle

Contents:

  • Application Overview
  • Background
  • Metadata Key-Value Pairs
  • Setup
  • Usage
    • Example Files
    • Example Usage
    • Statistics
    • Classtype
    • Filename
    • Disabled Rules
    • Normalize
    • Enhance
      • Detection Direction
    • Modify Metadata
    • Post Filter Modification
  • Boolean Filter Strings
    • Matching on the msg Field
    • Matching on the raw rule
    • Example Filter Strings
  • Post Filter Modification (“PFMod”)
    • Overview
    • PFMod YAML Format
      • PFMod Actions
    • Example PFMod YAML Files
  • Disabled/Commented Rules
    • Identification
    • Input
    • Output
  • Aristotle as a Module
    • Ruleset
      • Ruleset.add_metadata()
      • Ruleset.cve_compare()
      • Ruleset.delete_metadata()
      • Ruleset.evaluate()
      • Ruleset.filter_ruleset()
      • Ruleset.get_all_sids()
      • Ruleset.get_disabled_sids()
      • Ruleset.get_enabled_sids()
      • Ruleset.get_sids()
      • Ruleset.get_stats()
      • Ruleset.normalize_better()
      • Ruleset.output_rules()
      • Ruleset.parse_rules()
      • Ruleset.print_header()
      • Ruleset.print_ruleset_summary()
      • Ruleset.print_stats()
      • Ruleset.reduce_ipval()
      • Ruleset.set_metadata_filter()
  • License
  • Authors
Aristotle
  • Index

Index

A | C | D | E | F | G | N | O | P | R | S

A

  • add_metadata() (aristotle.Ruleset method)

C

  • cve_compare() (aristotle.Ruleset method)

D

  • delete_metadata() (aristotle.Ruleset method)

E

  • evaluate() (aristotle.Ruleset method)

F

  • filter_ruleset() (aristotle.Ruleset method)

G

  • get_all_sids() (aristotle.Ruleset method)
  • get_disabled_sids() (aristotle.Ruleset method)
  • get_enabled_sids() (aristotle.Ruleset method)
  • get_sids() (aristotle.Ruleset method)
  • get_stats() (aristotle.Ruleset method)

N

  • normalize_better() (aristotle.Ruleset method)

O

  • output_rules() (aristotle.Ruleset method)

P

  • parse_rules() (aristotle.Ruleset method)
  • print_header() (aristotle.Ruleset method)
  • print_ruleset_summary() (aristotle.Ruleset method)
  • print_stats() (aristotle.Ruleset method)

R

  • reduce_ipval() (aristotle.Ruleset method)
  • Ruleset (class in aristotle)

S

  • set_metadata_filter() (aristotle.Ruleset method)

© Copyright 2019 Secureworks, Inc., 2023 Uber Technologies, Inc..

Built with Sphinx using a theme provided by Read the Docs.