We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 8643e00 commit 7f6959eCopy full SHA for 7f6959e
detections/endpoint/network_connection_discovery_with_arp.yml
@@ -12,8 +12,17 @@ data_source:
12
- Windows Event Log Security 4688
13
- CrowdStrike ProcessRollup2
14
search: |-
15
- | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE
16
- Processes.process_name="arp.exe"
+ | tstats `security_content_summariesonly`
+ count min(_time) as firstTime
17
+ max(_time) as lastTime
18
+
19
+ FROM datamodel=Endpoint.Processes WHERE
20
21
+ (
22
+ Processes.process_name="arp.exe"
23
+ OR
24
+ Processes.process_original_file_name="arp.exe"
25
+ )
26
Processes.process IN (
27
"* -a*",
28
"* -g *",
0 commit comments