Skip to content

Commit 9e5557a

Browse files
authored
Add missing custom documentation fields to logoff security events (#645)
* update custom documentation * add generated file
1 parent 522becc commit 9e5557a

File tree

2 files changed

+12
-0
lines changed

2 files changed

+12
-0
lines changed

custom_documentation/doc/endpoint/security/windows/windows_security_log_off.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,13 +51,19 @@ This event is generated when a user logs off of the computer.
5151
| process.Ext.code_signature.status |
5252
| process.Ext.code_signature.subject_name |
5353
| process.Ext.code_signature.trusted |
54+
| process.Ext.protection |
5455
| process.Ext.session_info.logon_type |
56+
| process.Ext.token.integrity_level_name |
5557
| process.code_signature.exists |
5658
| process.code_signature.status |
5759
| process.code_signature.subject_name |
5860
| process.code_signature.trusted |
61+
| process.command_line |
5962
| process.entity_id |
6063
| process.executable |
64+
| process.name |
65+
| process.parent.executable |
66+
| process.pid |
6167
| user.domain |
6268
| user.effective.domain |
6369
| user.effective.email |

custom_documentation/src/endpoint/data_stream/security/windows/windows_security_log_off.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,13 +55,19 @@ fields:
5555
- process.Ext.code_signature.status
5656
- process.Ext.code_signature.subject_name
5757
- process.Ext.code_signature.trusted
58+
- process.Ext.protection
5859
- process.Ext.session_info.logon_type
60+
- process.Ext.token.integrity_level_name
5961
- process.code_signature.exists
6062
- process.code_signature.status
6163
- process.code_signature.subject_name
6264
- process.code_signature.trusted
65+
- process.command_line
6366
- process.entity_id
6467
- process.executable
68+
- process.name
69+
- process.parent.executable
70+
- process.pid
6571
- user.domain
6672
- user.effective.domain
6773
- user.effective.email

0 commit comments

Comments
 (0)