event PUS_started:
key:
event_src.host
filter {
(
(
msgid == "4688"
and event_src.title == "windows"
)
or (
msgid == "ProcessStarted"
and event_src.title == "endpoint_monitor"
)
or (
msgid == "1"
and event_src.title == "sysmon"
)
)
and exec_query("CheckUnwantedSoftware", [
lower(
object.name),
lower(object.path),
lower(object.value),
lower(object.hash)
])
and not exec_query("CheckSpecificValueWhitelist", [
lower(event_src.host),
lower(
subject.id),
lower(
object.name),
lower(object.hash)
])
}