Templates:
Sigma Generic Format v1.0
Detection Field Reference
Modifier Reference
Condition Syntax
selection — match all1 of selection* — any namedall of them — all selectionsselection and not filterselection1 or selection2selection | count() > 5