mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 10:13:57 +00:00
51df5ad876
Sumo Logic CSE Rule Backend Updated: Mapping depence on logsource Azure Sentinel Query Backend MDATP: query with few logsources CROWDSTRIKE: fix generateMapItemTypedNode
9 lines
181 B
YAML
9 lines
181 B
YAML
title: Sysmon
|
|
order: 20
|
|
backends:
|
|
- sysmon
|
|
fieldmappings:
|
|
event_id: EventID
|
|
event_data.ParentImage: ParentImage
|
|
event_data.CommandLine: CommandLine
|
|
event_data.Image: Image |