Update hawk.yml

This commit is contained in:
frack113
2022-12-23 20:59:40 +01:00
committed by GitHub
parent b53f534d2f
commit 316aa03efd
+1 -1
View File
@@ -171,7 +171,7 @@ logsources:
category: file_change
conditions:
product_name: "Sysmon"
vendor_id: "11"
vendor_id: "2"
windows-pipe-created:
product: windows
category: pipe_created