OTRF / OSSEM

Open Source Security Events Metadata (OSSEM)

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Sysmon data dictionary Update

Cyb3rPandaH opened this issue · comments

  • Event id 3: Field name DestinationHostName is missing.
    image

  • Event id 15: Field name Hashes should be changed to Hash based on the event XML.
    image

  • In events 1, 2, 3, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 17, 18 the field name RuleName is missing. The standard name might be tag
    image

Thank you @cyb3rpanda ! 👍