Detection Rules

SIEM detection rules and tuning

SO
Sigma • detection logic16 lines

Test against a sample event

Paste a JSON event and evaluate this rule before going live.

Sample event (JSON)
Result
Click "Run test" to evaluate the rule.