Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save faststeak/824a9bad9b0a0784f51ed9767b6e9810 to your computer and use it in GitHub Desktop.
Save faststeak/824a9bad9b0a0784f51ed9767b6e9810 to your computer and use it in GitHub Desktop.
Splunk Endpoint DM search for regsvr32.exe activity
| tstats summariesonly=true allow_old_summaries=true count from datamodel=Endpoint.Processes where Processes.process_name="regsvr32.exe" by _time Processes.dest Processes.parent_process Processes.process span=15m
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment