Skip to content

Commit 45d5f3b

Browse files
authored
Update README.md
1 parent f2b70b5 commit 45d5f3b

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

README.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -39,10 +39,14 @@ RootA is designed to welcome all members of cyber defence industry, maximising t
3939
You can start writing RootA rules in any code editor that supports YAML.
4040
To translate RootA rules to other languages use Uncoder.IO by building it from source https://github.com/UncoderIO/UncoderIO or hosted online privately by SOC Prime since 2018 at https://uncoder.io
4141

42-
RootA is designed with broad customization opportunities. Use the RootA minimal template if you just need to capture seamless cross-platform query translation into any SIEM, EDR, or XDR native format. Alternatively, apply full or short RootA templates to document your security use case in detail and share the research with peers.
43-
4442
### RootA Rule Templates
45-
You can get started by using one of the available rule templates, including full, short, or minimum, based on your current needs.
43+
RootA Rule format has minimal, full and extended templates.
44+
45+
**Minimal** template is for keeping rules simple, requiring only a name, description, author, severity, date, MITRE ATT&CK tags, detection query in any specific language, reference and license.
46+
47+
**Full** template is for adding alerting context, threat actor campaign timeline, specific log source attributes defined based on Sigma Rules or AWS OCSF taxonomy, and cross-platform correlation section.
48+
49+
**Extended** template is currently reserved for adding response as code and experimental features.
4650

4751
#### Minimal RootA rule example:
4852
```

0 commit comments

Comments
 (0)