Skip to content

Does all windows sigma rules requires Sysmon Logs..? #4110

Closed Answered by nasbench
Logeshrathinakumar asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

The short answer is. It depends on the logsource. You can use the following Taxonomy files to know which logs/events are required for each logsource as a starting point. https://github.com/SigmaHQ/sigma-specification/blob/main/Taxonomy_specification.md

We're working on a log source guide for every log with its specific fields. We will publish an initial version of this in the next few weeks (hopefully).

Hope this answers your questions.

[Small Update]
If I might also add while the fields are inspired by Sysmon sometime. The idea is fro you to map those fields to the closest thing that your EDR offers which in most case is very similar.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by nasbench
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants