mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update win_susp_regedit_trustedinstaller.yml
This commit is contained in:
parent
d1582944a7
commit
61f5e66569
@ -1,6 +1,6 @@
|
||||
title: Regedit as Trusted Installer
|
||||
id: 883835a7-df45-43e4-bf1d-4268768afda4
|
||||
description: Detects a regedit started with TrustedInstaller privileges
|
||||
description: Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
|
||||
references:
|
||||
- https://twitter.com/1kwpeter/status/1397816101455765504
|
||||
author: Florian Roth
|
||||
@ -11,7 +11,9 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
Image|endswith: '\regedit.exe'
|
||||
ParentImage|endswith: '\TrustedInstaller.exe'
|
||||
ParentImage|endswith:
|
||||
- '\TrustedInstaller.exe'
|
||||
- '\ProcessHacker.exe'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unlikely
|
||||
|
Loading…
Reference in New Issue
Block a user