Closed reswob10 closed 5 years ago
file_sha1 file_md5 file_sha256
If there are hashes. Remember, sysmon event_id 1 hashes the file executed.
NVM, I see hash is listed separately...
file_sha1 file_md5 file_sha256
If there are hashes. Remember, sysmon event_id 1 hashes the file executed.