rule: moved DebugView rule to process creation category
This commit is contained in:
+1
-2
@@ -7,11 +7,10 @@ references:
|
||||
author: Florian Roth
|
||||
date: 2020/05/28
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
service: sysmon
|
||||
detection:
|
||||
selection:
|
||||
EventID: 1
|
||||
Product:
|
||||
- 'Sysinternals DebugView'
|
||||
- 'Sysinternals Debugview'
|
||||
Reference in New Issue
Block a user