SOLVED

Add Custom Detections via api?

%3CLINGO-SUB%20id%3D%22lingo-sub-2690289%22%20slang%3D%22en-US%22%3EAdd%20Custom%20Detections%20via%20api%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2690289%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20it%20possible%20to%20add%20our%20own%20Custom%20Detections%2C%20either%20Sigma%20Rules%20or%20indicators%20from%20MISP%20via%20the%20api%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20is%20this%20the%20best%20place%20to%20ask%20questions%20and%20learn%3F%26nbsp%3B%20Is%20there%20a%20slack%20channel%2C%20discord%20chat%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2690289%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECustom%20Detections%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2703986%22%20slang%3D%22en-US%22%3ERe%3A%20Add%20Custom%20Detections%20via%20api%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2703986%22%20slang%3D%22en-US%22%3EYes%20-%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fmicrosoftgraph%2Fsecurity-api-solutions%2Fblob%2Fmaster%2FSamples%2FMISP%2FREADME.md%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2Fmicrosoftgraph%2Fsecurity-api-solutions%2Fblob%2Fmaster%2FSamples%2FMISP%2FREADME.md%3C%2FA%3E%3CBR%20%2F%3ESome%20warnings%3A%3CBR%20%2F%3EIt%20probably%20won't%20work%20out%20of%20the%20box.%3CBR%20%2F%3EYou'll%20need%20to%20take%20from%20what%20you%20see%20here%20and%20modify%2Fmake%20your%20own.%3CBR%20%2F%3E%3CBR%20%2F%3ESigma%20used%20to%20have%20a%20converter%20function%20for%20Endpoint%20%2C%20but%20like%20the%20script%20above%2C%20has%20fallen%20out%20of%20date.%20You%20could%20write%20your%20own%20converter%20though.%3C%2FLINGO-BODY%3E
Occasional Contributor

Is it possible to add our own Custom Detections, either Sigma Rules or indicators from MISP via the api?  

 

Thank you! 

 

Also, is this the best place to ask questions and learn?  Is there a slack channel, discord chat? 

1 Reply
best response confirmed by mathurin68 (Occasional Contributor)
Solution
Yes - https://github.com/microsoftgraph/security-api-solutions/blob/master/Samples/MISP/README.md
Some warnings:
It probably won't work out of the box.
You'll need to take from what you see here and modify/make your own.

Sigma used to have a converter function for Endpoint , but like the script above, has fallen out of date. You could write your own converter though.