Hello,
My Sysmon registry events (Registry object added or deleted (rule: RegistryEvent)
) seem to be missing an event.category
field. (7.8)
What event.category
should be given to these Sysmon events?
Grtz
Willem
Hello,
My Sysmon registry events (Registry object added or deleted (rule: RegistryEvent)
) seem to be missing an event.category
field. (7.8)
What event.category
should be given to these Sysmon events?
Grtz
Willem
Hello @willemdh ! Indeed it seems we lack a category value for registry related events. I opened an issue here to keep track of how we can improve this.
Thanks for bringing this up!
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.