Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Renderer ¶
type Renderer struct {
Headers []string
Row func(ScanResult) []string
}
Renderer defines the table/CSV columns for a specific log type. JSON output always serialises the full ScanResult struct.
type ScanResult ¶
type ScanResult struct {
Timestamp string `json:"Timestamp"`
Message string `json:"Message,omitempty"`
User string `json:"User,omitempty"`
Exe string `json:"Exe,omitempty"`
Terminal string `json:"Terminal,omitempty"`
PID string `json:"PID,omitempty"`
Tags []string `json:"Tags"`
Author string `json:"Author"`
RuleID string `json:"ID"`
Title string `json:"Title"`
}
ScanResult is the common result produced by all log mappers after evaluating Sigma rules.
Click to show internal directories.
Click to hide internal directories.