Elastic high stable kql
Threat Intel Windows Registry Indicator Match
This rule is triggered when a Windows registry indicator from the Threat Intel Filebeat module or integrations has a match against an event that contains registry data.
Detection Logic
registry.path:* Field Validations
Loading…
Comments (0)
Loading comments...