Changed category names and remove sysmon log source
This commit is contained in:
@@ -13,7 +13,6 @@ date: 2017/03/04
|
||||
logsource:
|
||||
category: process_access
|
||||
product: windows
|
||||
service: sysmon
|
||||
definition: 'Use the following config to generate the necessary Event ID 10 Process Access events: <ProcessAccess onmatch="include"><CallTrace condition="contains">VBE7.DLL</CallTrace></ProcessAccess><ProcessAccess onmatch="exclude"><CallTrace condition="excludes">UNKNOWN</CallTrace></ProcessAccess>'
|
||||
detection:
|
||||
selection:
|
||||
|
||||
Reference in New Issue
Block a user