EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
272 stars 59 forks source link

Update Security_Microsoft-Windows-Security-Auditing_4688.map #186

Closed esecrpm closed 2 years ago

esecrpm commented 2 years ago

Description

ProcessId and NewProcessId fields were reversed NewProcessId = Process ID ProcessId = Parent Process ID

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

Thank you for your submission and for contributing to the DFIR community!

AndrewRathbun commented 2 years ago

Good catch. Thank you