mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Added detection testing service results inBatch File Write to System32
This commit is contained in:
@@ -13,11 +13,11 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint
|
||||
Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [|
|
||||
tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*",
|
||||
"*\\syswow64\\*") Filesystem.file_name="*.bat"
|
||||
by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name
|
||||
Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time
|
||||
file_name file_path process_name process_path process] | dedup file_create_time
|
||||
| table dest file_create_time, file_name, file_path, process_name | `batch_file_write_to_system32_filter`'
|
||||
"*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest
|
||||
Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)`
|
||||
| fields _time dest file_create_time file_name file_path process_name process_path
|
||||
process] | dedup file_create_time | table dest file_create_time, file_name, file_path,
|
||||
process_name | `batch_file_write_to_system32_filter`'
|
||||
how_to_implement: You must be ingesting data that records the file-system activity
|
||||
from your hosts to populate the Endpoint file-system data-model node. If you are
|
||||
using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which
|
||||
|
||||
Reference in New Issue
Block a user