Skip to content

Documentation update for Playbook #1535

Locked Answered by defensivedepth
greatapoc asked this question in General
Discussion options

You must be logged in to vote

hey there @greatapoc

I have updated the documentation based on what you posted. Please let me know if there is something else in particular that we need to get update/documented. As you said, documentation is a never-ending task.

The current default plays rely only on Sysmon & Windows Eventlogs - you are seeing network Plays because Sysmon can generate network-related logs (Event ID 3). The Ruleset field on a Play corresponds to it's top-level category from the community ruleset we pull from (https://github.com/Neo23x0/sigma/tree/master/rules) - currently just windows

I have also created an issue for the docs link, thanks for pointing that out: #1552

Finally - please be aware of the perfo…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants