Files
splunk-security_content/macros/process_reg.yml
2021-08-17 12:09:31 -06:00

3 lines
222 B
YAML

definition: (Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)
description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/
name: process_reg