add EventID 26
This commit is contained in:
@@ -143,7 +143,9 @@ logsources:
|
||||
category: file_delete
|
||||
product: windows
|
||||
conditions:
|
||||
EventID: 23
|
||||
EventID:
|
||||
- 23
|
||||
- 26
|
||||
rewrite:
|
||||
product: windows
|
||||
service: sysmon
|
||||
|
||||
Reference in New Issue
Block a user