Persistence
1 events across 1 channel
Event ID 1337 —
#Fields #
| Name | Description |
|---|---|
Data | — |
Example Event #
{
"system": {
"provider": "Persistence",
"guid": "",
"event_source_name": "",
"event_id": 1337,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-05-24T04:59:06.909801+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Key Management Service",
"computer": "YamatoSecurity",
"security": {
"user_id": ""
}
},
"event_data": {
"Data": [
"FCE8820000006089E531C0648B50308B520C8B52148B72280FB74A2631FFAC3C617C022C20C1CF0D01C7E2F252578B52108B4A3C8B4C1178E34801D1518B592001D38B4918E33A498B348B01D631FFACC1CF0D01C738E075F6037DF83B7D2475E4588B582401D3668B0C4B8B581C01D38B048B01D0894424245B5B61595A51FFE05F5F5A8B12EB8D5D6A018D85B20000005068318B6F87FFD5BBF0B5A25668A695BD9DFFD53C067C0A80FBE07505BB4713726F6A0053FFD563616C632E65786500"
]
},
"message": ""
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx