We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 07df567 commit 6f4026bCopy full SHA for 6f4026b
detections/endpoint/windows_anonymous_pipe_activity.yml
@@ -10,8 +10,8 @@ data_source:
10
- Sysmon EventID 17
11
- Sysmon EventID 18
12
search: '`sysmon` EventCode IN (17,18) PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
13
- | stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature Image process_id process_guid EventType
14
- | rename Image as process_name
+ | rename Image as process_name
+ | stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature process_name process_id process_guid EventType
15
| `security_content_ctime(firstTime)`
16
| `security_content_ctime(lastTime)`
17
| `windows_anonymous_pipe_activity_filter`'
0 commit comments