Detection rules › By event

Microsoft-Windows-Sysmon Event ID 17

36 detection rules reference this event. View event page.

Sigma (20)

Elastic (1)

Splunk (10)

Kusto (3)

YARA-L (2)