We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 6f4026b commit bd04197Copy full SHA for bd04197
detections/endpoint/windows_anonymous_pipe_activity.yml
@@ -10,7 +10,7 @@ data_source:
10
- Sysmon EventID 17
11
- Sysmon EventID 18
12
search: '`sysmon` EventCode IN (17,18) PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
13
- | rename Image as process_name
+ | rename Image as process_name
14
| stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName signature process_name process_id process_guid EventType
15
| `security_content_ctime(firstTime)`
16
| `security_content_ctime(lastTime)`
0 commit comments