Files
blue-team-tools/tests/mapping-conditional-multi.yml
T
2018-10-16 14:53:12 +02:00

15 lines
349 B
YAML

title: Contional mapping with multiple targets
status: test
description: Logpoint configuration causes conditional mapping with multiple results
author: Thomas Patzke
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
SubjectAccountName: Test
condition: selection
fields:
- EventID