Files
splunk-security_content/macros/process_diskshadow.yml
2022-02-17 10:12:50 -06:00

3 lines
243 B
YAML

definition: (Processes.process_name=diskshadow.exe OR Processes.original_file_name=diskshadow.exe)
description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/
name: process_diskshadow