New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
windows: add support for sysmon 15.0/event 29 #6761
Conversation
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
8bac4e8
to
3a25c7b
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
"ecs": { | ||
"version": "8.0.0" | ||
}, | ||
"event": { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think it would be nice to have an event.action
populated with the sysmon event name like FileExecutableDetected
. But none of the other events have it at the moment either.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'll send another change for that.
Test case generated from XML document provided by user in elastic#6748.
Package windows - 1.25.0 containing this change is available at https://epr.elastic.co/search?package=windows |
Test case generated from XML document provided by user in #6748.
What does this PR do?
Adds a test case for sysmon 15.0/event 29.
Checklist
changelog.yml
file.Author's Checklist
How to test this PR locally
Related issues
Screenshots