From 785225a8ab40363fcc8f8cc47b1ed1ec5a63420c Mon Sep 17 00:00:00 2001 From: Kevin Branch Date: Fri, 23 Jun 2023 17:52:57 -0400 Subject: [PATCH] corrected field name case in 200150-sysmon_for_linux_rules.xml fixed incorrect case on system.eventId to system.eventID --- Sysmon Linux/200150-sysmon_for_linux_rules.xml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/Sysmon Linux/200150-sysmon_for_linux_rules.xml b/Sysmon Linux/200150-sysmon_for_linux_rules.xml index 59305e2..78323ab 100644 --- a/Sysmon Linux/200150-sysmon_for_linux_rules.xml +++ b/Sysmon Linux/200150-sysmon_for_linux_rules.xml @@ -7,7 +7,7 @@ sysmon-linux - \.+ + \.+ Sysmon For Linux Event T1204 @@ -17,7 +17,7 @@ 200150 - ^1$ + ^1$ Sysmon - Event 1: Process creation $(eventdata.image) sysmon_event1 @@ -28,7 +28,7 @@ 200150 - ^3$ + ^3$ Sysmon - Event 3: Network connection by $(eventdata.image) sysmon_event3 @@ -39,7 +39,7 @@ 200150 - ^5$ + ^5$ Sysmon - Event 5: Process terminated $(eventdata.image) sysmon_event5 @@ -50,7 +50,7 @@ 200150 - ^9$ + ^9$ Sysmon - Event 9: Raw Access Read by $(eventdata.image) sysmon_event9 @@ -61,7 +61,7 @@ 200150 - ^11$ + ^11$ Sysmon - Event 11: FileCreate by $(eventdata.image) sysmon_event_11 @@ -72,7 +72,7 @@ 200150 - ^16$ + ^16$ Sysmon - Event 16: Sysmon config state changed $(Event.EventData.Data.Configuration) sysmon_event_16 @@ -83,7 +83,7 @@ 200150 - ^23$ + ^23$ Sysmon - Event 23: FileDelete (A file delete was detected) by $(eventdata.image) sysmon_event_23