SigmaHQ/tests/collection_repeat.yml
Thomas Patzke e90ff2d991 Improved testing
* Added collection test case
* Test of file output
2017-11-01 21:14:11 +01:00

24 lines
394 B
YAML

---
action: global
title: Sigma Collection Test
description: Test all features of Sigma collections
---
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
CommandLine: cmd.exe
condition: selection
---
action: repeat
logsource:
product: windows
service: security
detection:
selection:
EventID: 4688
---
action: reset