mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
adding converted version
This commit is contained in:
+1
-1
@@ -35,7 +35,7 @@ search: ' | from read_ba_enriched_events() | eval timestamp = ucast(map_get(inpu
|
||||
any>", null) | eval device_hostname=ucast(map_get(device,"hostname"), "string",
|
||||
null) | where (process_file_name="powershell_ise.exe" OR process_file_name="powershell.exe"
|
||||
OR process_file_name="sqltoolsps.exe" OR process_file_name="sqlps.exe" OR process_file_name="pwsh.exe")
|
||||
AND match_regex(process_cmd_line, /(?i)[\-|\/]w(in*d*o*w*s*t*y*l*e*)*\s+h/)=true
|
||||
AND match_regex(process_cmd_line, /(?i)[\\-|\\/]w(in*d*o*w*s*t*y*l*e*)*\\s+h(i*d*d*e*n*)\\s+/)=true
|
||||
--finding_report--'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
|
||||
Reference in New Issue
Block a user