02e9c082df
* [New Rule] Potential SharpRdp Detected * Updated references * added process execution to the sequence added process execution to the sequence to capture the malicious process details that was executed * Linted * adjusted sequence * linted * adjusted process exec details to avoid procs termination * Update rules/windows/lateral_movement_rdp_sharprdp_target.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_rdp_sharprdp_target.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_rdp_sharprdp_target.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_rdp_sharprdp_target.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_rdp_sharprdp_target.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * eql syntax * eql syntax * ecs_version Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>