Skip to content

Commit 1f21a60

Browse files
SamirbousAegrah
andauthored
Update rules/windows/credential_access_lsass_openprocess_api.toml
Co-authored-by: Ruben Groenewoud <[email protected]>
1 parent bd97ee1 commit 1f21a60

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rules/windows/credential_access_lsass_openprocess_api.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -140,6 +140,7 @@ from logs-endpoint.events.api-*, logs-m365_defender.event-* metadata _id, _versi
140140
Esql.count_distinct_hosts = count_distinct(host.id),
141141
Esql.host_id_values = VALUES(host.id),
142142
Esql.process_pid_values = VALUES(process.entity_id),
143+
Esql.data_stream_namespace.values = VALUES(data_stream.namespace),
143144
Esql.user_name_values = VALUES(user.name) by Esql.process_path
144145
145146
// Limit to rare instances

0 commit comments

Comments
 (0)