Update sysmon_uac_bypass_eventvwr.yml

This commit is contained in:
Jonhnathan 2020-11-20 01:41:20 -03:00 committed by GitHub
parent e8aa9a854a
commit 372f000b7f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -24,8 +24,8 @@ logsource:
category: registry_event
detection:
methregistry:
- TargetObject|startswith: 'HKU\'
- TargetObject|endswith: '\mscfile\shell\open\command'
TargetObject|startswith: 'HKU\'
TargetObject|endswith: '\mscfile\shell\open\command'
condition: methregistry
---
logsource: