fix service from system to security for rule win_pcap_drivers.yml
This commit is contained in:
@@ -12,7 +12,7 @@ tags:
|
||||
- attack.t1040
|
||||
logsource:
|
||||
product: windows
|
||||
service: system
|
||||
service: security
|
||||
detection:
|
||||
selection:
|
||||
EventID: 4697
|
||||
|
||||
Reference in New Issue
Block a user