Understanding SIGMA Rule
Condition Operators
Example: 1 - Logical "OR"
### Example-1 Condition with Logical "OR"
title: Suspicious ‘mshta.exe’ Process Executions via Command Line tools
detection:
selection1:
EventID: 7045
ServiceName: 'PSEXESVC'
ServiceFileName: '\PSEXESVC.exe'
selection2:
EventID: 7036
ServiceName: 'PSEXESVC'
selection3:
EventID: 1
Image: '*\PSEXESVC.exe'
User: 'NT AUTHORITY\SYSTEM'
Condition: selection1 OR selection2 OR selection3Operators (1/any of Search-Identifiers)
Example: 2 - Logical "AND"
Operators (all of search-identifier)
Example: 3 - Negation with "NOT"
Example: 4 - Logical "AND/OR"
Example: 5 - Complete Rule (All of Above)

Last updated