File tree Expand file tree Collapse file tree 1 file changed +2
-5
lines changed Expand file tree Collapse file tree 1 file changed +2
-5
lines changed Original file line number Diff line number Diff line change @@ -10,8 +10,7 @@ data_source:
10
10
- Sysmon EventID 17
11
11
- Sysmon EventID 18
12
12
search : ' `sysmon` EventCode IN (17,18) PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
13
- | rename Image as process_name
14
- | stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature process_name process_id process_guid EventType
13
+ | stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature Image EventType
15
14
| `security_content_ctime(firstTime)`
16
15
| `security_content_ctime(lastTime)`
17
16
| `windows_anonymous_pipe_activity_filter`'
44
43
- field : user
45
44
type : user
46
45
score : 30
47
- threat_objects :
48
- - field : process_name
49
- type : process_name
46
+ threat_objects : []
50
47
tags :
51
48
analytic_story :
52
49
- SnappyBee
You can’t perform that action at this time.
0 commit comments