Detection Template
1 2 3 4 5
For an example of the above template, check out: WMIC WinRM LOLBin Execution by Provider Host
For defining the severity, check out: Alert Prioritization Framework
For the response plan, check out Alert Triage
For tagging, check out these useful links/tools:
Relevant Note(s):