Skip to content

Add a Sigma rule for credential-exfil detections #6

Description

@blitzcrieg1

Detections stream to SIEMs as canonical events (action.type: detection). A Sigma rule lets Splunk/Elastic users alert on the flagship one out of the box.

Task

Add docs/integrations/sigma/agentmetry_credential_exfil.yml matching action.type == "detection" AND detection.rule_id == "credential-exfil", mapped to ATT&CK T1552 / TA0010. Follow the format of the existing files in that folder and link it from docs/integrations/sigma/README.md.

Acceptance criteria

  • Valid Sigma YAML consistent with the existing pack.
  • Linked in the Sigma README.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions