mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
e2050404bc
This prevents EventID collision for this rule with other sources/logs that share the same EventIDs. specifically a lot with Microsoft-Windows-Security-SPP |
||
---|---|---|
.. | ||
builtin | ||
malware | ||
other | ||
powershell | ||
process_creation | ||
sysmon |