mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Fixed rule
This commit is contained in:
parent
666e859d14
commit
15a4c7e477
@ -4,11 +4,11 @@ references:
|
||||
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil
|
||||
- https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_mal_lockergoga.yml
|
||||
- https://abuse.io/lockergoga.txt
|
||||
author: @neu5ron, Florian Roth
|
||||
author: '@neu5ron, Florian Roth'
|
||||
date: 2019/03/22
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.T1070
|
||||
- attack.t1070
|
||||
level: high
|
||||
logsource:
|
||||
category: process_creation
|
||||
|
Loading…
Reference in New Issue
Block a user