NSACryptEvents collector retrieves Windows events log information from Microsoft-Windows-Audit-CVE provider.
Field | Type | Description |
|---|---|---|
id | Number | The process system identifier. |
process_id | Number | ID given by operating system to the process. |
thread_id | Number | The thread ID spawned by the process. |
time_created | Timestamp | Time when the event was created. |
message | String | CVE associated with the vulnerability for which this event is created. |
HostInfo hostname and NSACryptEvents where NSACryptEvents id not equals ""
Strings in conditions and filters are case insensitive: "software" and "SOFTWARE" match the same registry entries.
HostInfo hostname and NSACryptEvents where NSACryptEvents id not equals ""
Strings in conditions and filters are case insensitive: "software" and "SOFTWARE" match the same registry entries.