zeek, swap path and name

This commit is contained in:
neu5ron 2020-05-19 04:35:30 -04:00
parent 4446c4cd4e
commit 2fc8d513d6
6 changed files with 11 additions and 11 deletions

View File

@ -16,8 +16,8 @@ logsource:
service: smb_files
detection:
selection:
name: \\*\IPC$
path: atsvc
path: \\*\IPC$
name: atsvc
#Accesses: '*WriteData*'
condition: selection
falsepositives:

View File

@ -13,8 +13,8 @@ logsource:
service: smb_files
detection:
selection:
name: '\\*ADMIN$'
path: '*SYSTEM32\\*.tmp'
path: '\\*ADMIN$'
name: '*SYSTEM32\\*.tmp'
condition: selection
falsepositives:
- 'unknown'

View File

@ -14,10 +14,10 @@ logsource:
service: smb_files
detection:
selection1:
name: \\*\IPC$
path: \\*\IPC$
selection2:
name: \\*\IPC$
path:
path: \\*\IPC$
name:
- 'atsvc'
- 'samr'
- 'lsarpc'

View File

@ -13,8 +13,8 @@ logsource:
service: smb_files
detection:
selection1:
name: \\*\IPC$
path:
path: \\*\IPC$
name:
- '*-stdin'
- '*-stdout'
- '*-stderr'

View File

@ -11,7 +11,7 @@ logsource:
service: smb_files
detection:
selection:
path:
name:
- '*.pst'
- '*.ost'
- '*.msg'

View File

@ -13,7 +13,7 @@ logsource:
service: smb_files
detection:
selection:
path:
name:
- '\mimidrv'
- '\lsass'
- '\windows\minidump\'