securityonion
securityonion copied to clipboard
FIX: Sigmac Field Mappings
product: windows
category: raw_access_thread
product: windows
category: create_stream_hash
product: windows
category: create_remote_thread
CF: https://github.com/Security-Onion-Solutions/securityonion/discussions/8105
product: windows category: wmi_event
From Play 492 "WMI Event Subscription" (id: 0f06a3a5-6a09-413f-8743-e6cf35561297)
product: windows category: file_block (Sysmon EventID 27)
"Sysmon Blocked Executable" (id: 23b71bc5-953e-4971-be4c-c896cda73fc2)