mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
21 lines
397 B
YAML
21 lines
397 B
YAML
title: Qualys
|
|
order: 20
|
|
backends:
|
|
- qualys
|
|
fieldmappings:
|
|
dst:
|
|
- network.remote.address.ip
|
|
dst_ip:
|
|
- network.remote.address.ip
|
|
src:
|
|
- network.local.address.ip
|
|
src_ip:
|
|
- network.local.address.ip
|
|
file_hash:
|
|
- file.hash.md5
|
|
- file.hash.sha256
|
|
NewProcessName: process.name
|
|
ServiceName: process.name
|
|
ServiceFileName: process.name
|
|
TargetObject: registry.path
|