Merge pull request #1686 from leegengyu/patch-12

Update winlogbeat-modules-enabled.yml
This commit is contained in:
Florian Roth 2021-07-15 08:37:09 +02:00 committed by GitHub
commit 680e01d309
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -106,7 +106,7 @@ defaultindex: winlogbeat-*
# yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: winlog.event_data.\1/g' # yq -r '.detection | del(.condition) | map(keys) | .[][]' $(find sigma/rules/windows -name '*.yml') | sort -u | grep -v ^EventID$ | sed 's/^\(.*\)/ \1: winlog.event_data.\1/g'
# Keep EventID! Clean up the list afterwards! # Keep EventID! Clean up the list afterwards!
fieldmappings: fieldmappings:
EventID: winlog.event_id EventID: event.code
AccessMask: winlog.event_data.AccessMask AccessMask: winlog.event_data.AccessMask
AccountName: winlog.event_data.AccountName AccountName: winlog.event_data.AccountName
AllowedToDelegateTo: winlog.event_data.AllowedToDelegateTo AllowedToDelegateTo: winlog.event_data.AllowedToDelegateTo
@ -189,7 +189,7 @@ fieldmappings:
SubjectUserSid: user.id SubjectUserSid: user.id
TargetFilename: file.path TargetFilename: file.path
TargetImage: winlog.event_data.TargetImage TargetImage: winlog.event_data.TargetImage
TargetObject: winlog.event_data.TargetObject TargetObject: registry.path
TicketEncryptionType: winlog.event_data.TicketEncryptionType TicketEncryptionType: winlog.event_data.TicketEncryptionType
TicketOptions: winlog.event_data.TicketOptions TicketOptions: winlog.event_data.TicketOptions
TargetDomainName: user.domain TargetDomainName: user.domain