adding file event filter
This commit is contained in:
@@ -174,6 +174,12 @@ logsources:
|
||||
conditions:
|
||||
product_name: "Sysmon"
|
||||
vendor_id: "23"
|
||||
windows-file-event:
|
||||
product: windows
|
||||
category: file_event
|
||||
conditions:
|
||||
product_name: "Sysmon"
|
||||
vendor_id: 11
|
||||
windows-wmi-sysmon:
|
||||
product: windows
|
||||
category: wmi_event
|
||||
|
||||
Reference in New Issue
Block a user