Skip to content

SEC rulesets

Mina Gerges edited this page Jun 10, 2016 · 1 revision

Provided SEC rulesets

WinEvt_Dispatcher.sec

This ruleset acts as a dispatcher for Windows Event logs, using Perl function to extract event information into a hash table based on channel name. Hashtable is passed to specified ruleset for events parsing.

Clone this wiki locally