mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.0 KiB
1.0 KiB
Untitled string in Baseline Schema Schema
#/properties/how_to_implement#/properties/how_to_implement
information about how to implement. Only needed for non standard implementations.
| Abstract | Extensible | Status | Identifiable | Custom Properties | Additional Properties | Access Restrictions | Defined In |
|---|---|---|---|---|---|---|---|
| Can be instantiated | No | Unknown status | Unknown identifiability | Forbidden | Allowed | none | baselines.spec.json* |
how_to_implement Type
string
how_to_implement Examples
>-
This search requires Sysmon Logs and a Sysmon configuration, which includes
EventCode 10 for lsass.exe.