- Notifications
You must be signed in to change notification settings - Fork545
windows: add support for sysmon 15.0/event 29#6761
Conversation
elasticmachine commentedJun 30, 2023 • edited
Loading Uh oh!
There was an error while loading.Please reload this page.
edited
Uh oh!
There was an error while loading.Please reload this page.
elasticmachine commentedJun 30, 2023 • edited
Loading Uh oh!
There was an error while loading.Please reload this page.
edited
Uh oh!
There was an error while loading.Please reload this page.
🌐 Coverage report
|
elasticmachine commentedJun 30, 2023
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
8bac4e8 to3a25c7bCompare
ebeahan left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
I think it would be nice to have anevent.action populated with thesysmon event name likeFileExecutableDetected. But none of the other events have it at the moment either.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
I'll send another change for that.
Test case generated from XML document provided by user inelastic#6748.
elasticmachine commentedJul 9, 2023
Package windows - 1.25.0 containing this change is available athttps://epr.elastic.co/search?package=windows |
What does this PR do?
Adds a test case for sysmon 15.0/event 29.
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Related issues
Screenshots