Files
blue-team-tools/tests/collection_repeat.yml
T

24 lines
394 B
YAML
Raw Normal View History

2017-11-01 21:14:11 +01:00
---
action: global
title: Sigma Collection Test
description: Test all features of Sigma collections
---
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
CommandLine: cmd.exe
condition: selection
---
action: repeat
logsource:
product: windows
service: security
detection:
selection:
EventID: 4688
---
action: reset