Parser fields don't match detection query fileds
aleixsb opened this issue · 1 comments
aleixsb commented
Hi!
It's possible that the published parser is not the latest version? I'm seeing some inconsistencies with the fields parsed and the fields used at the queries, or I'm doing something wrong...
Ex:
Parser --> EventID
Detection --> event_id
Sysmon event 1
Parser --> process_parent_path
Detection --> process_parent_name