mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Merge pull request #706 from vesche/update_win_susp_netsh_dll_persistence
Update win_susp_netsh_dll_persistence.yml
This commit is contained in:
commit
5ee0808619
@ -3,10 +3,10 @@ id: 56321594-9087-49d9-bf10-524fe8479452
|
||||
description: Detects persitence via netsh helper
|
||||
status: test
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1060/T1060.yaml
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1128/T1128.md
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1060
|
||||
- attack.t1128
|
||||
date: 2019/10/25
|
||||
modified: 2019/10/25
|
||||
author: Victor Sergeev, oscd.community
|
||||
@ -26,5 +26,5 @@ fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
falsepositives:
|
||||
- Unkown
|
||||
- Unknown
|
||||
level: high
|
||||
|
Loading…
Reference in New Issue
Block a user