We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents 25c93ae + 9c81c5c commit e4dacb3Copy full SHA for e4dacb3
evtx/Maps/Security_4624.map
@@ -40,7 +40,14 @@ Maps:
40
-
41
Name: LogonType
42
Value: "/Event/EventData/Data[@Name=\"LogonType\"]"
43
+ -
44
+ Property: ExecutableInfo
45
+ PropertyValue: "%ProcessName%"
46
+ Values:
47
48
+ Name: ProcessName
49
+ Value: "/Event/EventData/Data[@Name=\"ProcessName\"]"
50
+
51
# Valid properties include:
52
# UserName
53
# RemoteHost
evtx/Maps/Security_4625.map
@@ -40,6 +40,14 @@ Maps:
0 commit comments