Skip to content

Commit 405064e

Browse files
authored
Update windows_process_execution_in_temp_dir.yml
1 parent dc9561d commit 405064e

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/windows_process_execution_in_temp_dir.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ data_source:
1414
- CrowdStrike ProcessRollup2
1515
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
1616
where Processes.process_path IN("*\\temp\\*")
17-
by Processes.parent_process_name Processes.process_nameProcesses.parent_process Processes.process_path Processes.dest Processes.user
17+
by Processes.parent_process_name Processes.process_name Processes.parent_process Processes.process_path Processes.dest Processes.user
1818
| `drop_dm_object_name(Processes)`
1919
| `security_content_ctime(firstTime)`
2020
| `security_content_ctime(lastTime)`

0 commit comments

Comments
 (0)