mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 10:13:57 +00:00
9 lines
181 B
YAML
9 lines
181 B
YAML
|
title: Sysmon
|
||
|
order: 20
|
||
|
backends:
|
||
|
- sysmon
|
||
|
fieldmappings:
|
||
|
event_id: EventID
|
||
|
event_data.ParentImage: ParentImage
|
||
|
event_data.CommandLine: CommandLine
|
||
|
event_data.Image: Image
|