santa icon indicating copy to clipboard operation
santa copied to clipboard

json 'pack' format to allow import/export of a group of rules

Open arubdesu opened this issue 7 years ago • 0 comments

Similar to how osquery collects common queries into 'packs' to be enabled in their config, it would be great to be able to import/export rules from the database as an option to santactl. Bonus points would be if output from santactl fileinfo was in that format to start with, so you could build up a collection from the results of fingerprinting a binary or its cert.

arubdesu avatar Aug 09 '16 16:08 arubdesu