Log source category
sysmon_status log source Sigma rules
1 Sigma detection rule in the library use the sysmon_status log source, mostly on windows. The sysmon_status category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
1 rule