Skip to content

Commit e4dacb3

Browse files
Merge pull request #24 from chadtilbury/master
Update 4624/4625 maps to include process name
2 parents 25c93ae + 9c81c5c commit e4dacb3

File tree

2 files changed

+16
-1
lines changed

2 files changed

+16
-1
lines changed

evtx/Maps/Security_4624.map

+8-1
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,14 @@ Maps:
4040
-
4141
Name: LogonType
4242
Value: "/Event/EventData/Data[@Name=\"LogonType\"]"
43-
43+
-
44+
Property: ExecutableInfo
45+
PropertyValue: "%ProcessName%"
46+
Values:
47+
-
48+
Name: ProcessName
49+
Value: "/Event/EventData/Data[@Name=\"ProcessName\"]"
50+
4451
# Valid properties include:
4552
# UserName
4653
# RemoteHost

evtx/Maps/Security_4625.map

+8
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,14 @@ Maps:
4040
-
4141
Name: LogonType
4242
Value: "/Event/EventData/Data[@Name=\"LogonType\"]"
43+
-
44+
Property: ExecutableInfo
45+
PropertyValue: "%ProcessName%"
46+
Values:
47+
-
48+
Name: ProcessName
49+
Value: "/Event/EventData/Data[@Name=\"ProcessName\"]"
50+
4351

4452
# Valid properties include:
4553
# UserName

0 commit comments

Comments
 (0)