Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Created September 21, 2017 16:56
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save MHaggis/a469c91d2869344e8dc32c6ab15f9e2a to your computer and use it in GitHub Desktop.
Save MHaggis/a469c91d2869344e8dc32c6ab15f9e2a to your computer and use it in GitHub Desktop.
# ingress.event.process
# ingress.event.procstart
# ingress.event.netconn
# ingress.event.procend
# ingress.event.childproc
# ingress.event.moduleload
# ingress.event.module
# ingress.event.filemod
# ingress.event.regmod
# ingress.event.tamper
# ingress.event.crossprocopen
# ingress.event.remotethread
# ingress.event.processblock
# ingress.event.emetmitigation
# watchlist.hit.process
# watchlist.hit.binary
# watchlist.storage.hit.process
# watchlist.storage.hit.binary
# feed.ingress.hit.process
# feed.ingress.hit.binary
# feed.ingress.hit.host
# feed.storage.hit.process
# feed.storage.hit.binary
# feed.query.hit.process
# feed.query.hit.binary
# alert.watchlist.hit.ingress.process
# alert.watchlist.hit.ingress.binary
# alert.watchlist.hit.ingress.host
# alert.watchlist.hit.query.process
# alert.watchlist.hit.query.binary
# binaryinfo.observed
# binaryinfo.host.observed
# binaryinfo.group.observed
# binarystore.file.added
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment