In this repository are Yara-L detection rules for Google Chronicle SIEM. These rules are either created by myself or compiled from other references, I do not take credit for every portion or logic within these rules.
- Please deploy these detections at your own risk.
- Log sources and parsing configuration differences will likely require that adjustments to these rules need to be made before the function properly.
- I highly advise tuning these rules to your environment before enabling alerting, some can be quite noisy.