Skip to content

Latest commit

 

History

History
31 lines (22 loc) · 1.01 KB

File metadata and controls

31 lines (22 loc) · 1.01 KB

process start

Schema ID: https://github.com/NextronSystems/jsonlog/thorlog/v3/eventlog-process-start | JSON Schema: https://json-schema.org/draft/2020-12/schema | Definition: EventlogProcessStart

Fields

Field names are shown in UPPERCASE as used in Sigma rules. The lowercase JSON name is shown in parentheses for reference.

Sigma Field JSON Name Type Required Description Example Values
PROCESS process string C:\Windows\SystemTemp\A01DF562-5405-4537..., C:\Windows\SoftwareDistribution\Download..., C:\Windows\System32\la57setup.exe
START_TIMES start_times array of string
TYPE type string

No nested fields in this type.

Sigma Rule Template

logsource:
    product: THOR
    service: "process start"

detection:
    selection:
        PROCESS|contains: 'suspicious_string'
    condition: selection

level: medium