Skip to content

Commit a1702c6

Browse files
tccontrenasbench
andauthored
Update detections/endpoint/windows_service_create_kernel_mode_driver.yml
Co-authored-by: Nasreddine Bencherchali <[email protected]>
1 parent db2d0ac commit a1702c6

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/windows_service_create_kernel_mode_driver.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ data_source:
1919
- CrowdStrike ProcessRollup2
2020
search: |
2121
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
22-
where Processes.process_name=sc.exe (Processes.process="*kernel*" OR Processes.process="*filesys*")
22+
where (Processes.process_name=sc.exe OR Processes.original_file_name=sc.exe) Processes.process IN ("*kernel*", "*filesys*") Processes.process="*type*"
2323
by Processes.action Processes.dest Processes.original_file_name
2424
Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid
2525
Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path

0 commit comments

Comments
 (0)