mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-08-20 22:48:21 +02:00
Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d2ff29b7a8 | ||
|
|
7bdaf9338e | ||
|
|
6f3f58bd70 |
@@ -2671,7 +2671,7 @@ soc:
|
|||||||
# The id (UUIDv4) is pregenerated and can safely be used.
|
# The id (UUIDv4) is pregenerated and can safely be used.
|
||||||
# Click "Convert" to convert the Sigma rule to use Security Onion field mappings within an EQL query
|
# Click "Convert" to convert the Sigma rule to use Security Onion field mappings within an EQL query
|
||||||
#
|
#
|
||||||
# Rule Creation Guide: https://github.com/SigmaHQ/sigma/wiki/Rule-Creation-Guide
|
# Rule Creation Guide: https://github.com/SigmaHQ/sigma/wiki/Rule-Creation-High%E2%80%90Level-Guide
|
||||||
# Logsources: https://sigmahq.io/docs/basics/log-sources.html
|
# Logsources: https://sigmahq.io/docs/basics/log-sources.html
|
||||||
|
|
||||||
title: 'A Short Capitalized Title With Less Than 50 Characters'
|
title: 'A Short Capitalized Title With Less Than 50 Characters'
|
||||||
@@ -2683,7 +2683,7 @@ soc:
|
|||||||
references:
|
references:
|
||||||
- 'https://local.invalid'
|
- 'https://local.invalid'
|
||||||
author: '@SecurityOnion'
|
author: '@SecurityOnion'
|
||||||
date: 'YYYY/MM/DD'
|
date: '[today]'
|
||||||
tags:
|
tags:
|
||||||
- detection.threat_hunting
|
- detection.threat_hunting
|
||||||
- attack.technique_id
|
- attack.technique_id
|
||||||
|
|||||||
Reference in New Issue
Block a user