Files
blue-team-tools/tools/config/qualys.yml
T

21 lines
397 B
YAML
Raw Normal View History

2019-05-16 23:33:51 +02:00
title: Qualys
2019-04-23 00:54:10 +02:00
order: 20
backends:
- qualys
2018-06-07 16:18:23 +03:00
fieldmappings:
dst:
- network.remote.address.ip
dst_ip:
- network.remote.address.ip
src:
- network.local.address.ip
src_ip:
- network.local.address.ip
file_hash:
- file.hash.md5
- file.hash.sha256
NewProcessName: process.name
ServiceName: process.name
ServiceFileName: process.name
TargetObject: registry.path