mirror of https://github.com/infosecn1nja/HELK.git
parent
a4d3a39a28
commit
eadc7aa810
|
@ -1,13 +0,0 @@
|
|||
alert:
|
||||
- debug
|
||||
description: Detects adversaries clearing logs via wevtutil
|
||||
filter:
|
||||
- query:
|
||||
query_string:
|
||||
query: (event_id:1 AND process_command_line:wevtutil AND process_command_line:cl)
|
||||
index: logs-endpoint-winevent-sysmon-*
|
||||
name: Windows-wevtutil-clear-logs_0
|
||||
priority: 2
|
||||
realert:
|
||||
minutes: 0
|
||||
type: any
|
Loading…
Reference in New Issue