File tree Expand file tree Collapse file tree 1 file changed +3
-3
lines changed Expand file tree Collapse file tree 1 file changed +3
-3
lines changed Original file line number Diff line number Diff line change 1
1
name : First Time Seen Child Process of Zoom
2
2
id : e91bd102-d630-4e76-ab73-7e3ba22c5961
3
- version : 7
4
- date : ' 2025-05-02 '
3
+ version : 8
4
+ date : ' 2025-05-15 '
5
5
author : David Dorsey, Splunk
6
6
status : experimental
7
7
type : Anomaly
@@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_
26
26
as process_exec values(Processes.process_guid) as process_guid values(Processes.process_hash)
27
27
as process_hash values(Processes.process_integrity_level) as process_integrity_level
28
28
values(Processes.process_name) as process_name values(Processes.process_path) as
29
- process_path values(Processes.user) as user values(Processes.user_id) as user_id
29
+ process_path values(Processes.user_id) as user_id
30
30
values(Processes.vendor_product) as vendor_product from datamodel=Endpoint.Processes
31
31
where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us)
32
32
by Processes.process_id Processes.dest | `drop_dm_object_name(Processes)` | lookup
You can’t perform that action at this time.
0 commit comments