Update win_mal_service_installs.yml - Add new Event ID

Added event ID 4697, which is equivalent to existing event ID 7045.
This commit is contained in:
G Y 2021-07-06 12:11:32 +08:00 committed by GitHub
parent c01ec60e7d
commit a0407cf477
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -22,7 +22,9 @@ logsource:
service: system
detection:
selection:
EventID: 7045
EventID:
- 4697
- 7045
malsvc_paexec:
ServiceFileName|contains: '\PAExec'
malsvc_wannacry: