Update hawk.yml
This commit is contained in:
@@ -171,7 +171,7 @@ logsources:
|
||||
category: file_change
|
||||
conditions:
|
||||
product_name: "Sysmon"
|
||||
vendor_id: "11"
|
||||
vendor_id: "2"
|
||||
windows-pipe-created:
|
||||
product: windows
|
||||
category: pipe_created
|
||||
|
||||
Reference in New Issue
Block a user