This commit is contained in:
JohnConnorRF 2021-05-05 10:25:36 -04:00
parent 3926e2388f
commit 1574d263cc

View File

@ -135,7 +135,7 @@ fieldmappings:
Product: winlog.event_data.Product
Properties: winlog.event_data.Properties
RuleName: winlog.event_data.RuleName
ScriptBlockText: winlog.event_data.ScriptBlockText
ScriptBlockText: powershell.file.script_block_text
SecurityID: winlog.event_data.SecurityID
ServiceFileName: winlog.event_data.ServiceFileName
ServiceName: winlog.event_data.ServiceName