Detection rules › By event

Microsoft-Windows-Sysmon Event ID 18

37 detection rules reference this event. View event page.

Sigma (20)

Splunk (10)

Kusto (5)

YARA-L (2)