mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 09:25:17 +00:00
87df79302d
Changed condition as follows: detection: selection: EventID: 4689 ProcessName|endswith: nltest.exe Status: "0x0" condition: selection Included field - SubjectDomainName |
||
---|---|---|
.. | ||
application | ||
apt | ||
cloud | ||
compliance | ||
generic | ||
linux | ||
network | ||
proxy | ||
web | ||
windows |