santa
santa copied to clipboard
json 'pack' format to allow import/export of a group of rules
Similar to how osquery collects common queries into 'packs' to be enabled in their config, it would be great to be able to import/export rules from the database as an option to santactl. Bonus points would be if output from santactl fileinfo
was in that format to start with, so you could build up a collection from the results of fingerprinting a binary or its cert.