Detections stream to SIEMs as canonical events (action.type: detection). A Sigma rule lets Splunk/Elastic users alert on the flagship one out of the box.
Task
Add docs/integrations/sigma/agentmetry_credential_exfil.yml matching action.type == "detection" AND detection.rule_id == "credential-exfil", mapped to ATT&CK T1552 / TA0010. Follow the format of the existing files in that folder and link it from docs/integrations/sigma/README.md.
Acceptance criteria
Detections stream to SIEMs as canonical events (
action.type: detection). A Sigma rule lets Splunk/Elastic users alert on the flagship one out of the box.Task
Add
docs/integrations/sigma/agentmetry_credential_exfil.ymlmatchingaction.type == "detection"ANDdetection.rule_id == "credential-exfil", mapped to ATT&CK T1552 / TA0010. Follow the format of the existing files in that folder and link it fromdocs/integrations/sigma/README.md.Acceptance criteria