mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
8b3b312c4e
This change removes dns events from the network connection category. The one change is that sysmon_regsvr32_network_activity.yml needs to test the network connection category separately from the DNS event id. |
||
---|---|---|
.. | ||
builtin | ||
deprecated | ||
driver_load | ||
file_event | ||
image_load | ||
malware | ||
network_connection | ||
other | ||
powershell | ||
process_access | ||
process_creation | ||
registry_event | ||
sysmon |