cscli collections install sigmahq/windows_proc_creationThis collection is an import from SigmaHQ (core) project rules related to Windows Process Creation.
Release: r2024-11-10
The process creation detection relies on Sysmon.
Example acquisition for this collection:
1source: wineventlog2pretty_name: sysmon3event_channel: "Microsoft-Windows-Sysmon/Operational"4labels:5 type: sysmon