Files
blue-team-tools/tools/config/generic/sysmon.yml
T

12 lines
268 B
YAML
Raw Normal View History

2019-05-16 23:33:51 +02:00
title: Conversion of generic rules into Sysmon
2019-04-23 00:54:10 +02:00
order: 10
logsources:
process_creation:
category: process_creation
product: windows
conditions:
EventID: 1
rewrite:
2018-09-12 23:31:51 +02:00
product: windows
service: sysmon