A library just onboarded Sysmon. Where should the analyst look first for process-creation and DNS-query detections already written for that sourcetype?
Select an answer to reveal the explanation.
Short Explanation
New Sysmon is like a new camera model—check the catalog before writing new film. SSE already has process-create and DNS-query content tagged for that sourcetype. Start there, not in the indexer-cluster panel.
Full Explanation
After a civic Sysmon onboard, the first content stop is Security Essentials filtered to the Sysmon sourcetype and the Endpoint CIM model. That is how analysts harvest existing process-creation and DNS-query detections instead of authoring from scratch. Indexer clustering and SOAR playbook editors are the wrong consoles for content discovery. A raw index=* probe is not a substitute for the catalog.