diff --git a/templates/TECHNIQUE_TEMPLATE.md b/templates/TECHNIQUE_TEMPLATE.md index be16d4da..10d76300 100644 --- a/templates/TECHNIQUE_TEMPLATE.md +++ b/templates/TECHNIQUE_TEMPLATE.md @@ -20,14 +20,14 @@ T0001_technique_name ## Recommended Data Sources -| ATT&CK Data Source | Event Log | Event ID| Description | -|---------|---------|---------|--------------| -|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | ID | FileCreate, Process access, etc.. | -|File Monitoring, Process Monitoring, etc..|Sysmon, WinEvent, PowerShell | ID | FileCreate, Process access, etc.. | -|File Monitoring, Process Monitoring, etc..|Sysmon, WinEvent, PowerShell | ID | FileCreate, Process access, etc.. | -|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | ID | FileCreate, Process access, etc.. | -|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | ID | FileCreate, Process access, etc.. | -|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | ID | FileCreate, Process access, etc.. | +| ATT&CK Data Source | Event Log | +|---------|---------| +|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | +|File Monitoring, Process Monitoring, etc..|Sysmon, WinEvent, PowerShell | +|File Monitoring, Process Monitoring, etc..|Sysmon, WinEvent, PowerShell | +|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | +|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell | +|File Monitoring, Process Monitoring, etc..| Sysmon, WinEvent, PowerShell |