diff --git a/evtx/Maps/SentinelOne-Operational_91.map b/evtx/Maps/SentinelOne-Operational_91.map new file mode 100644 index 00000000..b8c9da94 --- /dev/null +++ b/evtx/Maps/SentinelOne-Operational_91.map @@ -0,0 +1,56 @@ +Author: Tony Knutson +Description: Sentinel Remote Script Logging +EventId: 91 +Channel: "SentinelOne/Operational" +Provider: SentinelOne +Maps: + - + Property: ExecutableInfo + PropertyValue: "ScriptName: %ScriptName%" + Values: + - + Name: ScriptName + Value: "/Event/EventData/Data[@Name=\"ScriptName\"]" + - + Property: PayloadData1 + PropertyValue: "StartTime: %StartTime%" + Values: + - + Name: StartTime + Value: "/Event/EventData/Data[@Name=\"StartTime\"]" + - + Property: PayloadData3 + PropertyValue: "Duration: %Duration%" + Values: + - + Name: Duration + Value: "/Event/EventData/Data[@Name=\"Duration\"]" + +# Documentation: +# Script Logging Attempted +# +# Example Event Data: +# +# +# +# 31 +# 0 +# 3 +# 1 +# 0 +# 0x8000000000000000 +# +# 305 +# +# +# SentinelOne/Operational +# COMPUTERNAME +# +# +# +# SCRIPTNAME +# YYYY-MM-DD hh:mm:ss +# SSSS/Data> +# 0 +# +#