Skip to content

Commit 4c85acf

Browse files
tweak
1 parent 2d7c77c commit 4c85acf

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

playbook/dev/sigma/category/process_creation.yaml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,10 @@ description: |
44
Baseline Playbook for process creation events, OS agnostic. This playbook helps analysts investigate
55
any suspicious process execution by examining context, legitimacy, impact, and threat indicators.
66
Process creation alerts can range from legitimate administrative tools to known malware execution.
7-
type: sigma
8-
category: process_creation
7+
type: detection
8+
detection_id: ''
9+
detection_category: process_creation
10+
detection_type: sigma
911
contributors:
1012
- SecurityOnionSolutions
1113
date: 2025-05-29

0 commit comments

Comments
 (0)