We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents 556ff56 + 86f54f7 commit ef95025Copy full SHA for ef95025
tools/sigma/backends/mdatp.py
@@ -89,6 +89,7 @@ def __init__(self, *args, **kwargs):
89
"ParentName": ("InitiatingProcessFileName", self.default_value_mapping),
90
"ParentProcessName": ("InitiatingProcessFileName", self.default_value_mapping),
91
"ParentImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
92
+ "IntegrityLevel": ("ProcessIntegrityLevel", self.default_value_mapping),
93
"SourceImage": ("InitiatingProcessFolderPath", self.default_value_mapping),
94
"TargetImage": ("FolderPath", self.default_value_mapping),
95
"User": (self.decompose_user, ),
0 commit comments