gerrrt/opseclint detection-coverage

Analyze shell/command playbooks: map actions to ATT&CK techniques, host telemetry, and the detections that would fire.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathFile or directory to analyze.yes
platformTarget platform: linux-auditd | windows-sysmon | macos-es.nolinux-auditd
versionopseclint release to use (a tag like v0.1.0, or 'latest').nolatest
sarif-fileIf set, also write SARIF here (e.g. opseclint.sarif) for a code-scanning upload step.no""
fail-thresholdIf set (0-100), fail the job when the loudest action's detectability is >= this value.no""
argsExtra raw arguments passed through to opseclint.no""
namedescription
sarif-filePath to the SARIF file, when sarif-file was requested.