ivan ninichuck
1 min readJun 19, 2019

--

This is a brilliant workflow piece. I just started this process. I am somewhere between steps 1 and 2. My first step that really helped was creating a dashboard that just tracks what rules I am adding with the descriptions and tags. At first I felt worried I would lose track of what I was adding.

--

--

ivan ninichuck
ivan ninichuck

Written by ivan ninichuck

Passionate about all things cyber security. Especially working with the Elastic Stack for Threat Hunting, MITRE ATT&CK and Sigma Rules.

No responses yet