Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: Sysmon

Use-Case: Data Leak

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
10111
Event TypeRulesModels
file-writeT1114.001 - T1114.001
FA-Outlook-pst: A file ends with either pst or ost