Add logsource definition
This commit is contained in:
@@ -14,6 +14,7 @@ tags:
|
||||
logsource:
|
||||
category: file_access
|
||||
product: windows
|
||||
definition: file_access rules are using the Microsoft-Windows-Kernel-File ETW provider
|
||||
detection:
|
||||
selection:
|
||||
- FileName|contains:
|
||||
|
||||
@@ -13,6 +13,7 @@ tags:
|
||||
logsource:
|
||||
category: file_access
|
||||
product: windows
|
||||
definition: file_access rules are using the Microsoft-Windows-Kernel-File ETW provider
|
||||
detection:
|
||||
selection:
|
||||
FileName|contains:
|
||||
|
||||
@@ -13,6 +13,7 @@ tags:
|
||||
logsource:
|
||||
category: file_access
|
||||
product: windows
|
||||
definition: file_access rules are using the Microsoft-Windows-Kernel-File ETW provider
|
||||
detection:
|
||||
selection:
|
||||
FileName|contains:
|
||||
|
||||
@@ -13,6 +13,7 @@ tags:
|
||||
logsource:
|
||||
category: file_access
|
||||
product: windows
|
||||
definition: file_access rules are using the Microsoft-Windows-Kernel-File ETW provider
|
||||
detection:
|
||||
selection:
|
||||
FileName|endswith: '\Microsoft\Protect\CREDHIST'
|
||||
|
||||
Reference in New Issue
Block a user