Documentation ¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Relationship ¶
type Rule ¶
type Rule struct { Action Action `yaml:",omitempty"` Title string `yaml:",omitempty"` Id string `yaml:",omitempty"` Related []Relationship `yaml:",omitempty"` Status Status `yaml:",omitempty"` Description string `yaml:",omitempty"` Author string `yaml:",omitempty"` References []string `yaml:",omitempty"` LogSource LogSource `yaml:",omitempty"` Detection Detection `yaml:",omitempty"` Fields []field.Field `yaml:",omitempty"` FalsePositives []string `yaml:",omitempty"` Level Level `yaml:",omitempty"` Tags []string `yaml:",omitempty"` }
type Service ¶
type Service string
const ( ServiceSecurity Service = "security" ServiceSystem Service = "system" ServiceSysmon Service = "sysmon" ServiceTaskScheduler Service = "taskscheduler" ServiceWMI Service = "wmi" ServiceApplication Service = "application" ServiceDNSServer Service = "dns-server" ServiceDriverFramework Service = "driver-framework" ServicePowerShell Service = "powershell" ServicePowerShellClassic Service = "powershell-classic" ServiceAuth Service = "auth" ServiceAuditd Service = "auditd" ServiceClamAV Service = "clamav" ServiceAccess Service = "access" ServiceError Service = "error" )
Click to show internal directories.
Click to hide internal directories.