Remote Thread Ingress Event

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Remote Thread Ingress Event

Base Rule

Process/Service Started

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

VMID

<vmid>

Text/String

computer_name

<dname>

Text/String

md5

<objectname>

<hash>

Text/String

target_path

<process>

Text/String

target_process_id

<processid>

Number