SigmaHQ/tools/config/netwitness.yml

93 lines
1.7 KiB
YAML
Raw Normal View History

2019-05-16 21:33:51 +00:00
title: NetWitness
2019-04-22 22:54:10 +00:00
order: 20
backends:
- netwitness
2018-10-31 19:07:59 +00:00
logsources:
linux:
product: linux
conditions:
device.class: rhlinux
linux-sshd:
product: linux
service: sshd
conditions:
device.class: rhlinux
client: sshd
linux-auth:
product: linux
service: auth
conditions:
device.class: rhlinux
linux-clamav:
product: linux
service: clamav
conditions:
device.class: rhlinux
windows-sys:
product: windows
service: sysmon
conditions:
device.type: winevent_nic
event.source: microsoft-windows-security-auditing
windows-power:
product: windows
service: powershell
conditions:
device.type: winevent_nic
2019-02-05 13:35:16 +00:00
windows-dhcp:
product: windows
service: dhcp
conditions:
2019-02-05 13:35:16 +00:00
device.type: winevent_nic
event.source: microsoft-windows-dhcp-server
2018-10-31 19:07:59 +00:00
windows-sec:
product: windows
service: security
conditions:
device.type: winevent_nic
event.source: microsoft-windows-security-auditing
windows-system:
product: windows
service: system
conditions:
device.type: winevent_nic
fieldmappings:
dst:
2018-10-31 19:07:59 +00:00
- ip.dst
dst_ip:
- ip.dst
src:
- ip.src
src_ip:
- ip.src
DestinationPort:
- ip.dstport
EventID:
- reference.id
NewProcessName:
- process
LogonType:
- logon.type
AccountName:
- user.dst
c-uri-extension:
- extension
c-useragent:
2018-10-31 19:07:59 +00:00
- user.agent
r-dns:
- alias.host
DestinationHostname:
- alias.host
cs-host:
2018-10-31 19:07:59 +00:00
- alias.host
c-uri-query:
- web.page
c-uri:
2018-10-31 19:07:59 +00:00
- web.page
cs-method:
2018-10-31 19:07:59 +00:00
- action
cs-cookie:
2018-10-31 19:07:59 +00:00
- web.cookie
SubjectUserName:
- user.dst