mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
config: thor - powershell classic
This commit is contained in:
parent
03e2b9d376
commit
ba94b8396c
@ -176,6 +176,11 @@ logsources:
|
||||
service: powershell
|
||||
sources:
|
||||
- "WinEventLog:Microsoft-Windows-PowerShell/Operational"
|
||||
windows-classicpowershell:
|
||||
product: windows
|
||||
service: powershell-classic
|
||||
sources:
|
||||
- "WinEventLog:Windows PowerShell"
|
||||
windows-taskscheduler:
|
||||
product: windows
|
||||
service: taskscheduler
|
||||
|
Loading…
Reference in New Issue
Block a user