We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent dc9561d commit 405064eCopy full SHA for 405064e
detections/endpoint/windows_process_execution_in_temp_dir.yml
@@ -14,7 +14,7 @@ data_source:
14
- CrowdStrike ProcessRollup2
15
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
16
where Processes.process_path IN("*\\temp\\*")
17
- by Processes.parent_process_name Processes.process_nameProcesses.parent_process Processes.process_path Processes.dest Processes.user
+ by Processes.parent_process_name Processes.process_name Processes.parent_process Processes.process_path Processes.dest Processes.user
18
| `drop_dm_object_name(Processes)`
19
| `security_content_ctime(firstTime)`
20
| `security_content_ctime(lastTime)`
0 commit comments