Reordered fields

This commit is contained in:
Wietze 2020-05-02 14:46:55 +01:00
parent 661108903b
commit 5abf4cbea9

View File

@ -64,14 +64,13 @@ class WindowsDefenderATPBackend(SingleTextQueryBackend):
"ParentImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
"SourceImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
"TargetImage": ("FolderPath", self.default_value_mapping),
"TargetObject": ("RegistryKey", self.default_value_mapping),
"User": (self.decompose_user, ),
},
"DeviceEvents": {
"TargetFilename": ("FolderPath", self.default_value_mapping),
"TargetImage": ("FolderPath", self.default_value_mapping),
"Image": ("InitiatingFolderPath", self.default_value_mapping),
"TargetImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
"Image": ("InitiatingProcessFolderPath", self.default_value_mapping),
"User": (self.decompose_user, ),
},
"DeviceRegistryEvents": {
@ -79,8 +78,7 @@ class WindowsDefenderATPBackend(SingleTextQueryBackend):
"ObjectValueName": ("RegistryValueName", self.default_value_mapping),
"Details": ("RegistryValueData", self.default_value_mapping),
"Image": ("InitiatingFolderPath", self.default_value_mapping),
"TargetImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
"Image": ("InitiatingProcessFolderPath", self.default_value_mapping),
"User": (self.decompose_user, ),
},
"DeviceFileEvents": {