mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Adding ATT&CK tag
This commit is contained in:
parent
4d721f1803
commit
392351af25
@ -17,6 +17,10 @@ fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
- User
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.persistence
|
||||
- attack.t1158
|
||||
falsepositives:
|
||||
- igfxCUIService.exe hiding *.cui files via .bat script (attrib.exe a child of cmd.exe and igfxCUIService.exe is the parent of the cmd.exe)
|
||||
- msiexec.exe hiding desktop.ini
|
||||
|
Loading…
Reference in New Issue
Block a user