SigmaHQ/tools/config/sysmon.yml

9 lines
181 B
YAML
Raw Normal View History

title: Sysmon
order: 20
backends:
- sysmon
fieldmappings:
event_id: EventID
event_data.ParentImage: ParentImage
event_data.CommandLine: CommandLine
event_data.Image: Image