Skip to content

Commit 3f506e2

Browse files
authored
Merge pull request #43 from amadeuskonopko/master
Fix ConnectNamedPipe
2 parents 69c935b + 263d2a3 commit 3f506e2

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

parser/Sysmon-OSSEM.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -198,8 +198,8 @@ processEvents;
198198
let SysmonEvent18_ConnectNamedPipe=() {
199199
let processEvents = EventData
200200
| where EventID == 18
201-
| extend rule_name = EventDetail.[0].["#text"], event_creation_time = EventDetail.[1].["#text"], process_guid = EventDetail.[2].["#text"], process_id = EventDetail.[3].["#text"], pipe_name = EventDetail.[4].["#text"],
202-
process_path = EventDetail.[5].["#text"]
201+
| extend rule_name = EventDetail.[0].["#text"], event_creation_time = EventDetail.[2].["#text"], process_guid = EventDetail.[3].["#text"], process_id = EventDetail.[4].["#text"], pipe_name = EventDetail.[5].["#text"],
202+
process_path = EventDetail.[6].["#text"]
203203
| parse rule_name with * 'technique_id=' technique_id ',' * 'technique_name=' technique_name ',' * 'phase_name=' phase_name
204204
| project-away EventDetail, rule_name
205205
;

0 commit comments

Comments
 (0)