Renamed ProcessName field to Image for the process_creation category.

This commit is contained in:
Anton Kutepov
2021-02-25 01:57:26 +03:00
parent 96afd5845a
commit 98cc025208
43 changed files with 82 additions and 82 deletions
+2 -2
View File
@@ -13,12 +13,12 @@ logsource:
category: process_creation
detection:
selection1:
ProcessName|endswith:
Image|endswith:
- '/truncate'
CommandLine|contains:
- '-s'
selection2:
ProcessName|endswith:
Image|endswith:
- '/dd'
CommandLine|contains:
- 'if='