Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: aws_cloudtrail
description: Text that describe current mapping


log_source:
table:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: default
description: Text that describe current mapping



default_log_source:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: linux_file_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: linux_process_creation
description: Text that describe current mapping



default_log_source:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: macos_file_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: macos_process_creation
description: Text that describe current mapping



default_log_source:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Microsoft Sentinel
source: windows_file_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_image_load
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_process_creation
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_registry_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_security
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,2 @@
platform: Chronicle
source: default
description: Text that describe current mapping
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_create_remote_thread
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_dns_query
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_file_event
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_image_load
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_network_connection
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_pipe_created
description: Text that describe current mapping


field_mapping:
PipeName: target.resource.name
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_process_access
description: Text that describe current mapping


field_mapping:
TargetImage: target.process.file.full_path
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_process_creation
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_registry_event
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_security
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_sysmon
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: default
description: Text that describe current mapping


log_source:
event_simpleName:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: linux_dns_query
description: Text that describe current mapping


log_source:
event_simpleName: [DnsRequest]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: linux_network_connection
description: Text that describe current mapping


log_source:
event_simpleName: [NetworkConnectIP4]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: linux_process_creation
description: Text that describe current mapping


log_source:
event_simpleName: [ProcessRollup2]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: macos_dns_query
description: Text that describe current mapping


log_source:
event_simpleName: [DnsRequest]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: macos_network_connection
description: Text that describe current mapping


log_source:
event_simpleName: [NetworkConnectIP4]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: macos_process_creation
description: Text that describe current mapping


log_source:
event_simpleName: [ProcessRollup2]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_dns_query
description: Text that describe current mapping


log_source:
event_simpleName: [DnsRequest]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_driver_load
description: Text that describe current mapping


log_source:
event_simpleName: [DriverLoad]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_image_load
description: Text that describe current mapping


log_source:
event_simpleName: [LoadImage]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_network_connection
description: Text that describe current mapping


log_source:
event_simpleName: [NetworkConnectIP4]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_process_creation
description: Text that describe current mapping


log_source:
event_simpleName: [ProcessRollup2]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_registry_event
description: Text that describe current mapping


log_source:
event_simpleName: [RegistryOperationDetectInfo]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: aws_cloudtrail
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: aws_eks
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_AzureDiagnostics
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_BehaviorAnalytics
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_aadnoninteractiveusersigninlogs
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_azureactivity
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_azuread
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_m365
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_signinlogs
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: default
description: Text that describe current mapping


default_log_source:
index: "*"
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: dns
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: firewall
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: gcp_gcp.audit
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: gcp_pubsub
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Loading