We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 678fc4d commit a5010ccCopy full SHA for a5010cc
datasets/attack_techniques/T1222.001/fsutil_symlink_eval/fsutil_symlink_eval.yml
@@ -9,5 +9,5 @@ mitre_technique:
9
datasets:
10
- name: fsutil_symlink_eval.log
11
path: /datasets/attack_techniques/T1222.001/fsutil_symlink_eval/fsutil_symlink_eval.log
12
- sourcetypes: XmlWinEventLog
+ sourcetype: XmlWinEventLog
13
source: 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'
0 commit comments