SigmaHQ/tests/collection_repeat.yml

24 lines
394 B
YAML
Raw Normal View History

---
action: global
title: Sigma Collection Test
description: Test all features of Sigma collections
---
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
CommandLine: cmd.exe
condition: selection
---
action: repeat
logsource:
product: windows
service: security
detection:
selection:
EventID: 4688
---
action: reset