Files
blue-team-tools/tools/config/generic/windows-audit.yml
T

28 lines
773 B
YAML
Raw Normal View History

title: Conversion for Windows Native Auditing Events
2019-04-23 00:54:10 +02:00
order: 10
logsources:
process_creation:
category: process_creation
product: windows
conditions:
EventID: 4688
rewrite:
product: windows
service: security
registry_event:
category: registry_event
product: windows
conditions:
EventID: 4657
OperationType:
- 'New registry value created'
- 'Existing registry value modified'
rewrite:
product: windows
service: security
fieldmappings:
Image: NewProcessName
2019-01-16 23:37:18 +01:00
ParentImage: ParentProcessName
Details: NewValue
2021-11-10 19:12:51 +01:00
ParentCommandLine: ProcessCommandLine
LogonId: SubjectLogonId