Merge pull request #1909 from neu5ron/patch-8

condition fix and add fields
This commit is contained in:
frack113
2021-08-23 21:31:06 +02:00
committed by GitHub
@@ -20,10 +20,18 @@ logsource:
service: dce_rpc
detection:
efs_operation:
endpoint|startswith:
operation|startswith:
- 'Efs'
- 'efs'
condition: efs_operation
falsepositives:
- Uncommon but legitimate windows administrator or software tasks that make use of the Encrypting File System RPC Calls. Verify if this is common activity (see description).
level: medium
fields:
- id.orig_h
- id.resp_h
- id.resp_p
- operation
- endpoint
- named_pipe
- uid