Skip to content

Commit ef95025

Browse files
authored
Merge pull request SigmaHQ#4117 from alexmcdonald1124/mdatp-integrity-levels
feat: adding integrity level mapping for Microsoft Defender backend
2 parents 556ff56 + 86f54f7 commit ef95025

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

tools/sigma/backends/mdatp.py

+1
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,7 @@ def __init__(self, *args, **kwargs):
8989
"ParentName": ("InitiatingProcessFileName", self.default_value_mapping),
9090
"ParentProcessName": ("InitiatingProcessFileName", self.default_value_mapping),
9191
"ParentImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
92+
"IntegrityLevel": ("ProcessIntegrityLevel", self.default_value_mapping),
9293
"SourceImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
9394
"TargetImage": ("FolderPath", self.default_value_mapping),
9495
"User": (self.decompose_user, ),

0 commit comments

Comments
 (0)