mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_mal_service_installs.yml - Add new Event ID
Added event ID 4697, which is equivalent to existing event ID 7045.
This commit is contained in:
parent
c01ec60e7d
commit
a0407cf477
@ -22,7 +22,9 @@ logsource:
|
||||
service: system
|
||||
detection:
|
||||
selection:
|
||||
EventID: 7045
|
||||
EventID:
|
||||
- 4697
|
||||
- 7045
|
||||
malsvc_paexec:
|
||||
ServiceFileName|contains: '\PAExec'
|
||||
malsvc_wannacry:
|
||||
|
Loading…
Reference in New Issue
Block a user