Skip to content

Commit cc4c46b

Browse files
Add process.command_line to some windows file events (#616)
1 parent aef7d15 commit cc4c46b

File tree

4 files changed

+4
-0
lines changed

4 files changed

+4
-0
lines changed

custom_documentation/doc/endpoint/file/windows/windows_file_modification.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,7 @@ This event is generated when a file is modified.
6464
| process.code_signature.status |
6565
| process.code_signature.subject_name |
6666
| process.code_signature.trusted |
67+
| process.command_line |
6768
| process.entity_id |
6869
| process.executable |
6970
| process.name |

custom_documentation/doc/endpoint/file/windows/windows_file_overwrite.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,7 @@ This event is generated when a file is overwritten
6464
| process.code_signature.status |
6565
| process.code_signature.subject_name |
6666
| process.code_signature.trusted |
67+
| process.command_line |
6768
| process.entity_id |
6869
| process.executable |
6970
| process.name |

custom_documentation/src/endpoint/data_stream/file/windows/windows_file_modification.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,7 @@ fields:
6969
- process.code_signature.status
7070
- process.code_signature.subject_name
7171
- process.code_signature.trusted
72+
- process.command_line
7273
- process.entity_id
7374
- process.executable
7475
- process.name

custom_documentation/src/endpoint/data_stream/file/windows/windows_file_overwrite.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,7 @@ fields:
6969
- process.code_signature.status
7070
- process.code_signature.subject_name
7171
- process.code_signature.trusted
72+
- process.command_line
7273
- process.entity_id
7374
- process.executable
7475
- process.name

0 commit comments

Comments
 (0)