ocsf / ocsf-schema

OCSF Schema
Apache License 2.0
582 stars 118 forks source link

Adjust Entity Management class (3004) to be aligned with Windows event 4662 #1113

Closed eliraz-levi closed 3 weeks ago

eliraz-levi commented 3 weeks ago

Adjust Entity Management class (3004) to be aligned with fields exist in Windows event 4662 - “An operation was performed on an object”. https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4662

Related Issue:

https://github.com/ocsf/ocsf-schema/issues/1090

Description of changes:

We add the attributes access_list, access_mask. Screenshot 2024-06-04 at 15 50 27

Signed-off-by: Eliraz Levi eliraz.levi@hunters.ai