Skip to content

Commit 3f14df9

Browse files
tweak
1 parent 7476be0 commit 3f14df9

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

playbook/dev/sigma/category/process_creation.yaml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ questions:
7272
condition: selection
7373
fields:
7474
- User
75-
- CurrentWorkingDirectory
75+
- CurrentDirectory
7676
- Image
7777
- CommandLine
7878
@@ -95,7 +95,6 @@ questions:
9595
fields:
9696
- Image
9797
- CommandLine
98-
- event.action
9998
10099
- question: What files did this process create or modify?
101100
context: |

0 commit comments

Comments
 (0)