6d7df50d78
* Suspicious WMI Event Subscription Initial rule * Use EQL sequence * Update non-ecs-schema * Update persistence_sysmon_wmi_event_subscription.toml * update description Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * update query too look for even code 21 only * update to case sensitive compare * Update rules/windows/persistence_sysmon_wmi_event_subscription.toml Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com> * Update persistence_sysmon_wmi_event_subscription.toml * Update non-ecs-schema.json * Update rules/windows/persistence_sysmon_wmi_event_subscription.toml * Update non-ecs-schema.json * Update persistence_sysmon_wmi_event_subscription.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>