SigmaHQ/tests/mapping-conditional-multi.yml

16 lines
377 B
YAML
Raw Normal View History

title: Contional mapping with multiple targets
status: testing
description: Logpoint configuration causes conditional mapping with multiple results
author: Thomas Patzke
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
SubjectAccountName: Test
condition: selection
fields:
- EventID
2018-11-04 21:16:20 +00:00
- SubjectAccountName