Sysmon rules 'logsource' change

This commit is contained in:
Florian Roth
2017-02-19 09:19:06 +01:00
parent cd6e24c5ff
commit 166f207dc0
10 changed files with 10 additions and 17 deletions
@@ -2,8 +2,7 @@ title: Java running with Remote Debugging
description: Detcts a JAVA process running with remote debugging allowing more than just localhost to connect
author: Florian Roth
logsource:
- product: windows
- service: sysmon
- product: sysmon
detection:
selection:
EventLog: Microsoft-Windows-Sysmon/Operational