Files
splunk-security_content/macros/process_esentutl.yml
2021-08-18 11:14:13 -06:00

4 lines
238 B
YAML

definition: (Processes.process_name=esentutl.exe OR Processes.original_file_name=esentutl.exe)
description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/
name: process_esentutl