mirror of https://github.com/infosecn1nja/HELK.git
Minor Fix - Winevent Security
fix https://github.com/Cyb3rWard0g/HELK/issues/75keyword-vs-text-changes
parent
fea1b81c31
commit
2856a40c9c
|
@ -842,6 +842,13 @@ filter {
|
|||
tag_on_exception => "_0591_rubyexception"
|
||||
}
|
||||
}
|
||||
if [target_process_id] {
|
||||
mutate { gsub => [ "target_process_id", "0x", "" ]}
|
||||
ruby {
|
||||
code => "event.set('target_process_id', event.get('target_process_id').to_s.hex)"
|
||||
tag_on_exception => "_0591_rubyexception"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
|
Loading…
Reference in New Issue