SigmaHQ/tools/config/generic/sysmon.yml
2019-05-16 23:33:51 +02:00

12 lines
268 B
YAML

title: Conversion of generic rules into Sysmon
order: 10
logsources:
process_creation:
category: process_creation
product: windows
conditions:
EventID: 1
rewrite:
product: windows
service: sysmon