--- action: global title: Sigma Collection Test description: Test all features of Sigma collections --- logsource: product: windows service: sysmon detection: selection: EventID: 1 CommandLine: cmd.exe condition: selection --- action: repeat logsource: product: windows service: security detection: selection: EventID: 4688 --- action: reset