Main Sigma Rule Repository
Channel
field in ELK Windows configurationxpack-watcher
actions index and webhookcontains
alt
base64
base64offset
re
re
es-dsl
backendwdatp
xpack-watcher
backendutf16
utf16le
wide
utf16be
ala
es-dsl
wildcard querieses-dsl
backendsigma-similarity
tooles-dsl
backend (propagates to backends derived from this like elastalert-dsl)startswith
endswith
es-qs
backendes-qs
backendProcessCommandLine
mapping for Windows Security EventID 4688 in generic
process creation log source configuration