I see that @elastic startet to share their detection rules, which is great
— Florian Roth (@cyb3rops) July 1, 2020
We can already convert Sigma rules into their format (-t es-rule)
So, no need to learn a different format that has 97% of the fields & logic that a vendor-agnostic Sigma rule has.
We've got you covered. https://t.co/unSmpwHIIe pic.twitter.com/aGvSUZax5M