SigmaHQ / pySigma-backend-splunk

pySigma Splunk backend
GNU Lesser General Public License v2.1
34 stars 18 forks source link

Original file name addition #21

Closed Rivosyke closed 1 year ago

Rivosyke commented 1 year ago

Added OriginalFileName (Sysmon EID 1) mapping for Splunk CIM compliance. Also added OriginalFileName to the process creation datamodel test.

thomaspatzke commented 1 year ago

For some reason the tests still fail, it appears some regression to me but not clear yet, have to investigate further.