Closed zodf0055980 closed 3 years ago
In each case, there's exactly one attack.
So CVE-2020-0796-RCE-POC
AccessList in winlogbeat
is used to confuse?
Or it is a Typographical error.
It might appears in other logs too I believe. Just see which one is unique between those three and you will find the right class. If CVE-2020-0796-RCE-POC is not unique then simply ignore it in my opinion.
Hello, I find Attack_1,3,5 have
CVE-2020-0796-RCE-POC
AccessList inwinlogbeat
. It is mean one of Attack_1,3,5 hasMalicious Attachment
? If no repetitive attacks, Whywinlogbeat
have its accessList log?