The number of artifacts in the exchange is growing and we need to trim them a bit in order to increase quality.
The following guidelines make sense
- Artifacts the specifically search in event logs should be merged into the sigma project
- Artifacts the look in sqlite files should be merged in sqlitehunter
- Artifacts that run external tools should pin tool hashes
- Artifacts that look for specific threats should be removed once the threat is too old (e.g. log4j)
The number of artifacts in the exchange is growing and we need to trim them a bit in order to increase quality.
The following guidelines make sense