mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update sysmon_win_reg_persistence.yml
This commit is contained in:
parent
8a52610bf8
commit
229e57777a
@ -11,10 +11,10 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection_reg1:
|
||||
TargetObject:
|
||||
- '*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\*\GlobalFlag'
|
||||
- '*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\\*\ReportingMode'
|
||||
- '*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\\*\MonitorProcess'
|
||||
TargetObject|startswith:
|
||||
- '\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\\*\GlobalFlag'
|
||||
- '\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\\*\ReportingMode'
|
||||
- '\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\\*\MonitorProcess'
|
||||
EventType: SetValue
|
||||
condition: selection_reg1
|
||||
tags:
|
||||
|
Loading…
Reference in New Issue
Block a user