@@ -14,16 +14,16 @@ field_mapping:
1414AccessMask :AccessMask
1515AccountName :AccountName
1616AllowedToDelegateTo :AllowedToDelegateTo
17- AttributeLDAPDisplayName :
17+ AttributeLDAPDisplayName :AttributeLDAPDisplayName
1818AuditPolicyChanges :AuditPolicyChanges
1919AuthenticationPackageName :AuthenticationPackageName
2020CallingProcessName :CallingProcessName
2121Channel :Channel
2222ComputerName :Computer
2323EventType :EventType
2424FailureReason :FailureReason
25- FileName :FilePath
26- GrantedAccess :
25+ FileName :FileName
26+ GrantedAccess :GrantedAccess
2727Hashes :FileHash
2828HiveName :HiveName
2929IpAddress :IpAddress
@@ -48,83 +48,83 @@ field_mapping:
4848TaskContent :TaskContent
4949ServiceSid :ServiceSid
5050CertThumbprint :CertThumbprint
51- ClassName :duplicate
52- NotificationPackageName :ClassName
51+ ClassName :ClassName
52+ NotificationPackageName :NotificationPackageName
5353NewSd :NewSd
5454TestSigning :TestSigning
5555TargetInfo :TargetInfo
56- ClientProcessId :TargetInfo
56+ ClientProcessId :ClientProcessId
5757ParentProcessId :ParentProcessId
5858AccessList :AccessList
5959GroupMembership :GroupMembership
6060FilterName :FilterName
6161ChangeType :ChangeType
6262LayerName :LayerName
6363ServiceAccount :ServiceAccount
64- AttributeValue :ServiceAccount
64+ AttributeValue :AttributeValue
6565SessionName :SessionName
6666TaskName :TaskName
67- ObjectDN :SessionName
67+ ObjectDN :ObjectDN
6868TemplateContent :TemplateContent
6969NewTemplateContent :NewTemplateContent
70- SourcePort :TemplateContent
70+ SourcePort :SourcePort
7171PasswordLastSet :PasswordLastSet
7272PrivilegeList :PrivilegeList
73- DeviceDescription :PasswordLastSet
74- TargetServerName :PrivilegeList
75- NewTargetUserName :DeviceDescription
76- OperationType :TargetServerName
73+ DeviceDescription :DeviceDescription
74+ TargetServerName :TargetServerName
75+ NewTargetUserName :NewTargetUserName
76+ OperationType :OperationType
7777DestPort :DestPort
78- ServiceStartType :OperationType
78+ ServiceStartType :ServiceStartType
7979OldTargetUserName :OldTargetUserName
80- UserPrincipalName :ServiceStartType
80+ UserPrincipalName :UserPrincipalName
8181Accesses :Accesses
82- DnsHostName :UserPrincipalName
83- DisableIntegrityChecks :AccessList
82+ DnsHostName :DnsHostName
83+ DisableIntegrityChecks :DisableIntegrityChecks
8484AuditSourceName :AuditSourceName
8585Workstation :Workstation
8686DestAddress :DestAddress
87- PreAuthType :Workstation
87+ PreAuthType :PreAuthType
8888SecurityPackageName :SecurityPackageName
8989SubjectLogonId :SubjectLogonId
9090NewUacValue :NewUacValue
91- EnabledPrivilegeList :SubjectLogonId
92- RelativeTargetName :NewUacValue
91+ EnabledPrivilegeList :EnabledPrivilegeList
92+ RelativeTargetName :RelativeTargetName
9393CertSerialNumber :CertSerialNumber
94- SidHistory :RelativeTargetName
94+ SidHistory :SidHistory
9595TargetLogonId :TargetLogonId
96- KernelDebug :SidHistory
97- CallerProcessName :TargetLogonId
96+ KernelDebug :KernelDebug
97+ CallerProcessName :CallerProcessName
9898ProcessName :ProcessName
99- Properties :CallerProcessName
100- UserAccountControl :ProcessName
101- RegistryValue :Properties
102- SecurityID :UserAccountControl
99+ Properties :Properties
100+ UserAccountControl :UserAccountControl
101+ RegistryValue :RegistryValue
102+ SecurityID :SecurityID
103103ServiceFileName :ServiceFileName
104- SecurityDescriptor :SecurityID
105- ServiceName :ServiceFileName
106- ShareName :SecurityDescriptor
107- NewValue :ServiceName
108- Source :ShareName
109- Status :NewValue
104+ SecurityDescriptor :SecurityDescriptor
105+ ServiceName :ServiceName
106+ ShareName :ShareName
107+ NewValue :NewValue
108+ Source :Source
109+ Status :Status
110110SubjectDomainName :SubjectDomainName
111- SubjectUserName :Status
112- SubjectUserSid :SubjectDomainName
113- SourceAddr :SubjectUserName
114- SourceAddress :SubjectUserSid
111+ SubjectUserName :SubjectUserName
112+ SubjectUserSid :SubjectUserSid
113+ SourceAddr :SourceAddr
114+ SourceAddress :SourceAddress
115115TargetName :TargetName
116116ServicePrincipalNames :ServicePrincipalNames
117- TargetDomainName :TargetName
117+ TargetDomainName :TargetDomainName
118118TargetSid :TargetSid
119- TargetUserName :TargetDomainName
120- ObjectServer :TargetSid
121- TargetUserSid :TargetUserName
122- TicketEncryptionType :ObjectServer
123- TicketOptions :TargetUserSid
119+ TargetUserName :TargetUserName
120+ ObjectServer :ObjectServer
121+ TargetUserSid :TargetUserSid
122+ TicketEncryptionType :TicketEncryptionType
123+ TicketOptions :TicketOptions
124124WorkstationName :WorkstationName
125125TransmittedServices :TransmittedServices
126- AuthenticationAlgorithm :WorkstationName
127- LayerRTID :TransmittedServices
126+ AuthenticationAlgorithm :AuthenticationAlgorithm
127+ LayerRTID :LayerRTID
128128BSSID :BSSID
129129BSSType :BSSType
130130CipherAlgorithm :CipherAlgorithm
@@ -139,7 +139,7 @@ field_mapping:
139139Domain :Domain
140140ServiceType :ServiceType
141141SourceName :SourceName
142- StartType :ServiceType
142+ StartType :StartType
143143UserID :UserID
144144ParentProcessName :ParentProcessName
145145Service :Service