rule: moved DebugView rule to process creation category

This commit is contained in:
Florian Roth
2020-05-28 10:13:38 +02:00
parent 76dcc1a16f
commit 39b41b5582
@@ -7,11 +7,10 @@ references:
author: Florian Roth
date: 2020/05/28
logsource:
category: process_creation
product: windows
service: sysmon
detection:
selection:
EventID: 1
Product:
- 'Sysinternals DebugView'
- 'Sysinternals Debugview'