Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 828 Bytes

ff18353f-3a63-4ffb-aeff-bb2d5a4fadba.md

File metadata and controls

30 lines (23 loc) · 828 Bytes

Mappings: Windows - WMI - 5680

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Microsoft-Windows-WMI-Activity/Operational-5860

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
commandLine UserData.Operation_TemporaryEssStarted.Query
description RenderingInfo.Message
device_hostname Computer
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ
user_userId Security.UserID
user_username UserData.Operation_TemporaryEssStarted.User