When using the Windows Integration for collecting Sysmon logs, we found that Sysmon registry logs are not parsed if they are not DWORD or QWORD.
We had to drop sysmon support to various detection rules in elastic/detection-rules#1775 that were ineffective due to this limitation on the integration.
When using the Windows Integration for collecting Sysmon logs, we found that Sysmon registry logs are not parsed if they are not DWORD or QWORD.
We had to drop sysmon support to various detection rules in elastic/detection-rules#1775 that were ineffective due to this limitation on the integration.