Skip to content

[windows] Lacks parsing for Sysmon Registry non-QWORD/DWORD events #2864

@w0rk3r

Description

@w0rk3r

When using the Windows Integration for collecting Sysmon logs, we found that Sysmon registry logs are not parsed if they are not DWORD or QWORD.

We had to drop sysmon support to various detection rules in elastic/detection-rules#1775 that were ineffective due to this limitation on the integration.

Metadata

Metadata

Assignees

Labels

Integration:windowsWindowsbugSomething isn't working, use only for issues

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions