run_sigma_lineage
Run Sigma hunt rules on EVTX logs with process lineage tracing to produce actionable kill chain paths and summaries.
Instructions
Run Sigma hunt + process lineage tracing and return process_lineage paths/summary.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| levels | No | ||
| evtx_path | Yes | ||
| skip_hunt | No | ||
| output_dir | Yes | ||
| mapping_path | Yes | ||
| sigma_rules_path | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||