We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
id: 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
"Pipe Connected: eventID:18 EventType: ConnectPipe UtcTime: 2023-11-19 19:57:25.549 ProcessId: 2416 PipeName: \MICROSOFT##WID\tsql\query Image: C:\Windows\WID\Binn\sqlwriter.exe Microsoft-Windows-Sysmon"
This sysmon event with eventid: 18 is a common false positive.
The text was updated successfully, but these errors were encountered:
nasbench
Successfully merging a pull request may close this issue.
Rule UUID
id: 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
Example EventLog
"Pipe Connected:
eventID:18
EventType: ConnectPipe
UtcTime: 2023-11-19 19:57:25.549
ProcessId: 2416
PipeName: \MICROSOFT##WID\tsql\query
Image: C:\Windows\WID\Binn\sqlwriter.exe
Microsoft-Windows-Sysmon"
Description
This sysmon event with eventid: 18 is a common false positive.
The text was updated successfully, but these errors were encountered: