Data Source: Sysmon EventID 14

Description

Data source object for Sysmon EventID 14

Details

Property Value
Source XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sourcetype XmlWinEventLog
Separator EventID
Name ▲▼ Technique ▲▼ Type ▲▼
Windows Modify Registry to Add or Modify Firewall Rule Modify Registry Anomaly

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
</div>

Source: GitHub | Version: 2