YARA-L rule coverage

29 events across 5 providers with Google SecOps / Chronicle YARA-L detection rules, 285 rule mappings total. Each rule links to its own page (predicates, exclusions, shared indicators). For the rule-centric ATT&CK browse across every vendor, see all detection rules; non-Windows YARA-L rules are grouped by platform and technique at YARA-L non-Windows coverage.

Microsoft-Windows-Sysmon

Event ID 1 Process creation 69 rules
Event ID 2 A process changed a file creation time 2 rules
Event ID 3 Network connection 14 rules
Event ID 7 Image loaded 1 rule
Event ID 10 ProcessAccess 5 rules
Event ID 11 FileCreate 20 rules
Event ID 12 RegistryEvent (Object create and delete) 1 rule
Event ID 13 RegistryEvent (Value Set) 15 rules
Event ID 17 PipeEvent (Pipe Created) 2 rules
Event ID 18 PipeEvent (Pipe Connected) 2 rules
Event ID 22 DNSEvent (DNS query) 7 rules
Event ID 23 FileDelete (File Delete archived) 2 rules

Microsoft-Windows-Security-Auditing

Event ID 4624 An account was successfully logged on. 12 rules
Event ID 4625 An account failed to log on. 12 rules
Event ID 4648 A logon was attempted using explicit credentials. 12 rules
Event ID 4656 A handle to an object was requested. 1 rule
Event ID 4657 A registry value was modified. 15 rules
Event ID 4662 An operation was performed on an object. 1 rule
Event ID 4688 A new process has been created. 69 rules
Event ID 4697 A service was installed in the system. 1 rule
Event ID 4720 A user account was created. 1 rule
Event ID 4726 A user account was deleted. 1 rule
Event ID 5156 The Windows Filtering Platform has permitted a connection. 14 rules

ESENT

Event ID 216 1 rule
Event ID 325 1 rule
Event ID 326 1 rule
Event ID 327 1 rule

Microsoft-Windows-Eventlog

Event ID 1102 The audit log was cleared. 1 rule

Service-Control-Manager

Event ID 7045 1 rule