Skip to content

Commit

Permalink
update others_apt (#278)
Browse files Browse the repository at this point in the history
Signed-off-by: Grant Haywood <[email protected]>
Co-authored-by: Subhobrata Dey <[email protected]>
  • Loading branch information
phaseshiftg and sbcd90 authored Feb 20, 2023
1 parent a705168 commit 04e99a4
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 29 deletions.
7 changes: 2 additions & 5 deletions src/main/resources/OSMapping/others_apt/fieldmappings.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,4 @@
# this file provides pre-defined mappings for Sigma fields defined for all Sigma rules under apt log group to their corresponding ECS Fields.
fieldmappings:
EventID: event_uid
HiveName: unmapped.HiveName
fieldB: mappedB
fieldA1: mappedA
creationTime: timestamp
Image: process-exe
CommandLine: process-command_line
28 changes: 4 additions & 24 deletions src/main/resources/OSMapping/others_apt/mappings.json
Original file line number Diff line number Diff line change
@@ -1,32 +1,12 @@
{
"properties": {
"windows-event_data-CommandLine": {
"process-exe": {
"type": "alias",
"path": "CommandLine"
"path": "process.exe"
},
"event_uid": {
"process-command_line": {
"type": "alias",
"path": "EventID"
},
"windows-hostname": {
"type": "alias",
"path": "HostName"
},
"windows-message": {
"type": "alias",
"path": "Message"
},
"windows-provider-name": {
"type": "alias",
"path": "Provider_Name"
},
"windows-servicename": {
"type": "alias",
"path": "ServiceName"
},
"timestamp": {
"path": "creationTime",
"type": "alias"
"path": "process.command_line"
}
}
}

0 comments on commit 04e99a4

Please sign in to comment.