Sigma Rule Library

Log source category

process_creation log source Sigma rules

1632 Sigma detection rules in the library use the process_creation log source, mostly on windows, linux, macos. The process_creation category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.

1632 rules

Products

Severity