-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Taxonomy
Thomas Patzke edited this page Aug 2, 2018
·
14 revisions
This page defines field names and log sources that should be used to ensure sharable rules.
-
category: process_creation
: Defines a process creation event
-
product: windows
: Windows Operating System logs-
service: security
: Windows Security Event Log -
service: security
: Windows Security Event Log -
service: sysmon
: Event Logs created by Sysmon. Some may be covered by generic log sources
-