readme update
This commit is contained in:
@@ -566,7 +566,7 @@ detection:
|
|||||||
### Or ideally something like this:
|
### Or ideally something like this:
|
||||||
```yaml
|
```yaml
|
||||||
detection:
|
detection:
|
||||||
selection_basic_info:
|
selection_BasicInfo:
|
||||||
Channel: Security
|
Channel: Security
|
||||||
EventID: 4648
|
EventID: 4648
|
||||||
selection_TargetUserIsComputerAccount:
|
selection_TargetUserIsComputerAccount:
|
||||||
|
|||||||
@@ -564,7 +564,7 @@ detection:
|
|||||||
### 良い例:
|
### 良い例:
|
||||||
```yaml
|
```yaml
|
||||||
detection:
|
detection:
|
||||||
selection_basic_info:
|
selection_BasicInfo:
|
||||||
Channel: Security
|
Channel: Security
|
||||||
EventID: 4648
|
EventID: 4648
|
||||||
selection_TargetUserIsComputerAccount:
|
selection_TargetUserIsComputerAccount:
|
||||||
|
|||||||
Reference in New Issue
Block a user