mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Merge pull request #1686 from leegengyu/patch-12
Update winlogbeat-modules-enabled.yml
This commit is contained in:
commit
680e01d309
@ -106,7 +106,7 @@ defaultindex: winlogbeat-*
|
|||||||
# yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: winlog.event_data.\1/g'
|
# yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: winlog.event_data.\1/g'
|
||||||
# Keep EventID! Clean up the list afterwards!
|
# Keep EventID! Clean up the list afterwards!
|
||||||
fieldmappings:
|
fieldmappings:
|
||||||
EventID: winlog.event_id
|
EventID: event.code
|
||||||
AccessMask: winlog.event_data.AccessMask
|
AccessMask: winlog.event_data.AccessMask
|
||||||
AccountName: winlog.event_data.AccountName
|
AccountName: winlog.event_data.AccountName
|
||||||
AllowedToDelegateTo: winlog.event_data.AllowedToDelegateTo
|
AllowedToDelegateTo: winlog.event_data.AllowedToDelegateTo
|
||||||
@ -189,7 +189,7 @@ fieldmappings:
|
|||||||
SubjectUserSid: user.id
|
SubjectUserSid: user.id
|
||||||
TargetFilename: file.path
|
TargetFilename: file.path
|
||||||
TargetImage: winlog.event_data.TargetImage
|
TargetImage: winlog.event_data.TargetImage
|
||||||
TargetObject: winlog.event_data.TargetObject
|
TargetObject: registry.path
|
||||||
TicketEncryptionType: winlog.event_data.TicketEncryptionType
|
TicketEncryptionType: winlog.event_data.TicketEncryptionType
|
||||||
TicketOptions: winlog.event_data.TicketOptions
|
TicketOptions: winlog.event_data.TicketOptions
|
||||||
TargetDomainName: user.domain
|
TargetDomainName: user.domain
|
||||||
|
Loading…
Reference in New Issue
Block a user