You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think the score is even. I've had to further update the filter with the following as the CIM datamodel is inconsistent between Sysmon and the Security Channel:
NOT (Processes.os="Microsoft Windows" OR Processes.vendor_product="Microsoft Windows")
Describe the bug
The Linux Service Started Or Enabled rule can trigger on Windows events.
Expected behavior
Rule does not trigger on events from Windows Sysmon
Screenshots
App Version:
Additional context
I got a good laugh out of this.
Appending
NOT Processes.os="Microsoft Windows"
to the end of thewhere
clause seems sufficient for resolving this issue.The text was updated successfully, but these errors were encountered: