Skip to main content

Supported Attributes

AlphaSOC supports the following detection attributes in Sigma rules. These attributes can be used in both community and custom rules to define detection logic.

Sigma Basics

Modifiers

Modifiers transform field values during rule matching and enable flexible pattern matching in Sigma rules. The following table details AlphaSOC's current support status for each modifier:

ModifierSupport Status
allSUPPORTED
base64/base64offsetSUPPORTED
casedSUPPORTED
cidrSUPPORTED
containsSUPPORTED
endswithSUPPORTED
existsIN PROGRESS
expandNOT SUPPORTED
fieldrefSUPPORTED
gtSUPPORTED
gteSUPPORTED
ltSUPPORTED
lteSUPPORTED
reSUPPORTED
startswithSUPPORTED
utf16/utf16le/utf16be/wideNOT SUPPORTED
windashPARTIAL
Limited to 2 flags

Conditions

Conditions define the logical structure for combining field matches in Sigma rules using boolean operators and pattern matching. The following tables detail AlphaSOC's current support status for each condition:

Basic Conditions

ConditionSupport Status
notSUPPORTED
andSUPPORTED
orSUPPORTED
bracketsSUPPORTED

Advanced Conditions

ConditionSupport Status
1 of (search pattern)SUPPORTED
all of (search pattern)SUPPORTED
1 of themSUPPORTED
all of themSUPPORTED

Logsources

AlphaSOC maps external Sigma logsources to internal data origins.

Standard Logsources

The following Sigma Standard Logsources are supported:

Sigma logsourceProductCategoryServiceAlphaSOC Data Origin
AWSawscloudtrailAWS CloudTrail
AzureazureazureactivityAzure Activity
GCPgcpgcp.auditGCP Audit
OktaoktaoktaOkta
Microsoft365microsoft365portalauditlogsMicrosoft 365 PLANNING
WindowswindowsallallCrowdStrike FDR
macOSmacosprocess_creationCrowdStrike FDR
Linuxlinuxprocess_creationCrowdStrike FDR
LinuxlinuxsshdJournald
Zeekzeekhttp
dns
Zeek

For details on how data from these sources is processed and standardized, see Data Normalization. For specific field mappings between source data and AlphaSOC's internal format, refer to Product Field Mappings.

AlphaSOC Custom

AlphaSOC implements a custom logsource following Sigma's approach. This provides a filter mechanism to select events based on specific data origins, allowing rules to target particular data sources.

The AlphaSOC custom logsource uses the following format:

logsource:
product: alphasoc
service: [data_origin]

Where [data_origin] corresponds to any of the data origins supported by AlphaSOC. The following table lists all available data origins by product:

ProductData Origins
1Password1password-event-audit, 1password-item-audit, 1password-login-audit
Amazon Web Servicesaws-vpc-flow, aws-cloudtrail, aws-route53
Atlassianatlassian-audit
Azureazure-device-network, azure-nsg-flow, azure-vnet-flow, azure-activity-audit
Carbon Black Netconncarbonblack-netconn
Confluenceconfluence-audit
CrowdStrikecrowdstrike-aid-master, crowdstrike-data
DNSTapdnstap
GitHubgithub-audit
Google Cloud Platformgcp-vpc-flow, gcp-dns, gcp-kube-audit, gcp-audit
Google Security Operationsgoogle-secops-udm
Jirajira-audit
Kuberneteskube-audit
Microsoft 365microsoft-365-audit
Microsoft Entramicrosoft-entra-audit
Oktaokta-audit
Slackslack-audit
Systemd Journaljournald
Zeekzeek-conn, zeek-dns, zeek-http, zeek-ssl, zeek-dhcp