Skip to content

Commit d49440f

Browse files
committed
Removing duplicate creation of user
1 parent c599382 commit d49440f

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/first_time_seen_child_process_of_zoom.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_
2626
as process_exec values(Processes.process_guid) as process_guid values(Processes.process_hash)
2727
as process_hash values(Processes.process_integrity_level) as process_integrity_level
2828
values(Processes.process_name) as process_name values(Processes.process_path) as
29-
process_path values(Processes.user) as user values(Processes.user_id) as user_id
29+
process_path values(Processes.user_id) as user_id
3030
values(Processes.vendor_product) as vendor_product from datamodel=Endpoint.Processes
3131
where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us)
3232
by Processes.process_id Processes.dest | `drop_dm_object_name(Processes)` | lookup

0 commit comments

Comments
 (0)