Aristotle

Contents:

  • Application Overview
  • Background
  • Metadata Key-Value Pairs
  • Setup
  • Usage
    • Example Files
    • Example Usage
    • Statistics
    • Classtype
    • Filename
    • Disabled Rules
    • Normalize
    • Enhance
      • Detection Direction
    • Modify Metadata
    • Post Filter Modification
  • Boolean Filter Strings
    • Matching on the msg Field
    • Matching on the raw rule
    • Example Filter Strings
  • Post Filter Modification (“PFMod”)
    • Overview
    • PFMod YAML Format
      • PFMod Actions
    • Example PFMod YAML Files
  • Disabled/Commented Rules
    • Identification
    • Input
    • Output
  • Aristotle as a Module
    • Ruleset
      • Ruleset.add_metadata()
      • Ruleset.cve_compare()
      • Ruleset.delete_metadata()
      • Ruleset.evaluate()
      • Ruleset.filter_ruleset()
      • Ruleset.get_all_sids()
      • Ruleset.get_disabled_sids()
      • Ruleset.get_enabled_sids()
      • Ruleset.get_sids()
      • Ruleset.get_stats()
      • Ruleset.normalize_better()
      • Ruleset.output_rules()
      • Ruleset.parse_rules()
      • Ruleset.print_header()
      • Ruleset.print_ruleset_summary()
      • Ruleset.print_stats()
      • Ruleset.reduce_ipval()
      • Ruleset.set_metadata_filter()
  • License
  • Authors
Aristotle
  • Search


© Copyright 2019 Secureworks, Inc., 2023 Uber Technologies, Inc..

Built with Sphinx using a theme provided by Read the Docs.