We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 1d2e689 commit dba17e7Copy full SHA for dba17e7
detections/endpoint/suspicious_copy_on_system32.yml
@@ -22,7 +22,7 @@ data_source:
22
search:
23
'| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
24
as lastTime from datamodel=Endpoint.Processes where
25
- parent_process_name IN (
+ Processes.parent_process_name IN (
26
"cmd.exe",
27
"powershell_ise.exe",
28
"powershell.exe",
@@ -35,8 +35,8 @@ search:
35
"* \"C:\\Windows\\System32\\*",
36
"* \'C:\\Windows\\System32\\*",
37
"* C:\\Windows\\System32\\*",
38
- "* \"C:\\Windows\\SysWow64\\*"
39
- "* \'C:\\Windows\\SysWow64\\*"
+ "* \"C:\\Windows\\SysWow64\\*",
+ "* \'C:\\Windows\\SysWow64\\*",
40
"* C:\\Windows\\SysWow64\\*"
41
)
42
by Processes.action Processes.dest Processes.original_file_name
0 commit comments