Skip to content

Instantly share code, notes, and snippets.

What would you like to do?
sequence by, process.entity_id with maxspan=3s
[process where event.type == "start" and : "svchost.exe" and process.args : "appmodel"]
[network where event.action == "connection_accepted" and : "svchost.exe" and
source.port >= 49152 and destination.port >= 49152 and source.ip != "" and source.ip != "::1"]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment