Merge PR #5842 from @swachchhanda000 - chore: update thor.yml with missing file_change category
chore: update thor.yml with missing file_change category
This commit is contained in:
committed by
GitHub
parent
3d8c650ba2
commit
a4ddc7a414
@@ -25,6 +25,14 @@ logsources:
|
||||
fieldmappings:
|
||||
Image: NewProcessName
|
||||
ParentImage: ParentProcessName
|
||||
file_change:
|
||||
category: file_change
|
||||
product: windows
|
||||
conditions:
|
||||
EventID: 2
|
||||
rewrite:
|
||||
product: windows
|
||||
service: sysmon
|
||||
network_connection:
|
||||
category: network_connection
|
||||
product: windows
|
||||
|
||||
Reference in New Issue
Block a user