Skip to content

Commit 59189f4

Browse files
committed
headless_bee
1 parent fecfefe commit 59189f4

File tree

1 file changed

+2
-5
lines changed

1 file changed

+2
-5
lines changed

detections/endpoint/windows_anonymous_pipe_activity.yml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,7 @@ data_source:
1010
- Sysmon EventID 17
1111
- Sysmon EventID 18
1212
search: '`sysmon` EventCode IN (17,18) PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
13-
| rename Image as process_name
14-
| stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature process_name process_id process_guid EventType
13+
| stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature Image EventType
1514
| `security_content_ctime(firstTime)`
1615
| `security_content_ctime(lastTime)`
1716
| `windows_anonymous_pipe_activity_filter`'
@@ -44,9 +43,7 @@ rba:
4443
- field: user
4544
type: user
4645
score: 30
47-
threat_objects:
48-
- field: process_name
49-
type: process_name
46+
threat_objects: []
5047
tags:
5148
analytic_story:
5249
- SnappyBee

0 commit comments

Comments
 (0)