Ref #933 - Added windows Process Creation to config

This commit is contained in:
Sander 2020-07-16 13:16:57 +02:00
parent 254942e4c3
commit 6c35a7afa0
2 changed files with 10 additions and 0 deletions

View File

@ -29,6 +29,11 @@ logsources:
service: sysmon
conditions:
winlog.channel: 'Microsoft-Windows-Sysmon/Operational'
windows-process-creation:
product: windows
category: process_creation
conditions:
winlog.event_id: '1'
windows-dns-server:
product: windows
service: dns-server

View File

@ -28,6 +28,11 @@ logsources:
service: sysmon
conditions:
winlog.channel: 'Microsoft-Windows-Sysmon/Operational'
windows-process-creation:
product: windows
category: process_creation
conditions:
winlog.event_id: '1'
windows-dns-server:
product: windows
service: dns-server