Sigma Rule Library

Log source category

process_tampering log source Sigma rules

1 Sigma detection rule in the library use the process_tampering log source, mostly on windows. The process_tampering category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.

1 rule

Products

Severity