mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update ssa___credential_extraction_fgdump_cachedump_s_option.yml
This commit is contained in:
committed by
GitHub
parent
ff215bb999
commit
c9953b5c8a
@@ -24,7 +24,7 @@ search: ' | from read_ssa_enriched_events()
|
||||
|
||||
| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event,
|
||||
"dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"),
|
||||
"string", null)), body=create_map(["dest_user_id", dest_user_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();'
|
||||
"string", null)), body=create_map(["cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();'
|
||||
how_to_implement: You must be ingesting Windows Security logs from devices of interest,
|
||||
including the event ID 4688 with enabled command line logging.
|
||||
known_false_positives: None identified.
|
||||
|
||||
Reference in New Issue
Block a user