Elastic high stable kql

Threat Intel Windows Registry Indicator Match

This rule is triggered when a Windows registry indicator from the Threat Intel Filebeat module or integrations has a match against an event that contains registry data.

View Source

Detection Logic

registry.path:*

Field Validations

Loading…

Comments (0)

Loading comments...