diff --git a/windows/sysmon/events/event-1.yml b/windows/sysmon/events/event-1.yml
index a2b7b2cb4..b2e62ee7a 100644
--- a/windows/sysmon/events/event-1.yml
+++ b/windows/sysmon/events/event-1.yml
@@ -192,46 +192,46 @@ event_sample:
The publisher has been disabled and its resource is not available. This usually occurs when the publisher is in the process of being uninstalled or upgraded
- format: xml
sample: |-
-
-
-
- 1
- 5
- 4
- 1
- 0
- 0x8000000000000000
-
- 2472309
-
-
- Microsoft-Windows-Sysmon/Operational
- pedro-computer
-
-
-
- -
- 2022-09-23 00:00:46.275
- {564ff025-f72e-632c-c407-000000000500}
- 7860
- C:\Windows\System32\svchost.exe
- 10.0.18362.1 (WinBuild.160101.0800)
- Host Process for Windows Services
- Microsoft® Windows® Operating System
- Microsoft Corporation
- svchost.exe
- C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvc
- C:\Windows\system32\
- NT AUTHORITY\SYSTEM
- {564ff025-d424-62f6-e703-000000000000}
- 0x3e7
- 0
- System
- SHA1=75C5A97F521F760E32A4A9639A653EED862E9C61,MD5=9520A99E77D6196D0D09833146424113,SHA256=DD191A5B23DF92E12A8852291F9FB5ED594B76A28A5A464418442584AFD1E048,IMPHASH=247B9220E5D9B720A82B2C8B5069AD69
- {564ff025-d424-62f6-0b00-000000000500}
- 584
- C:\Windows\System32\services.exe
- C:\Windows\system32\services.exe
- NT AUTHORITY\SYSTEM
-
-
+
+
+
+ 1
+ 5
+ 4
+ 1
+ 0
+ 0x8000000000000000
+
+ 2472309
+
+
+ Microsoft-Windows-Sysmon/Operational
+ pedro-computer
+
+
+
+ -
+ 2022-09-23 00:00:46.275
+ {564ff025-f72e-632c-c407-000000000500}
+ 7860
+ C:\Windows\System32\svchost.exe
+ 10.0.18362.1 (WinBuild.160101.0800)
+ Host Process for Windows Services
+ Microsoft® Windows® Operating System
+ Microsoft Corporation
+ svchost.exe
+ C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvc
+ C:\Windows\system32\
+ NT AUTHORITY\SYSTEM
+ {564ff025-d424-62f6-e703-000000000000}
+ 0x3e7
+ 0
+ System
+ SHA1=75C5A97F521F760E32A4A9639A653EED862E9C61,MD5=9520A99E77D6196D0D09833146424113,SHA256=DD191A5B23DF92E12A8852291F9FB5ED594B76A28A5A464418442584AFD1E048,IMPHASH=247B9220E5D9B720A82B2C8B5069AD69
+ {564ff025-d424-62f6-0b00-000000000500}
+ 584
+ C:\Windows\System32\services.exe
+ C:\Windows\system32\services.exe
+ NT AUTHORITY\SYSTEM
+
+
diff --git a/windows/sysmon/events/event-15.yml b/windows/sysmon/events/event-15.yml
index d90fe87d4..c11ad7ad0 100644
--- a/windows/sysmon/events/event-15.yml
+++ b/windows/sysmon/events/event-15.yml
@@ -58,7 +58,7 @@ event_fields:
name: Contents
type: string
description: Content of the file
- sample_value: [ZoneTransfer] ZoneId=3 ReferrerUrl=Z:\files\last_sysmon\Sysmon.zip
+ sample_value: '[ZoneTransfer] ZoneId=3 ReferrerUrl=Z:\files\last_sysmon\Sysmon.zip'
references:
- text: Sysmon Source
link: https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-15-filecreatestreamhash
@@ -125,4 +125,4 @@ event_sample:
SHA1=000F277774DD28D7F4D00E174B4741F71D8828E4,MD5=2004CA2A9BFEBFB45B145B5D80B3FD76,SHA256=2AD30B0FA4239B95D7059A1E5D7BC16328F98B23C89D3A437A3F1661F05F82F0,IMPHASH=00000000000000000000000000000000
[ZoneTransfer] ZoneId=3 ReferrerUrl=Z:\files\last_sysmon\Sysmon.zip
-
\ No newline at end of file
+