mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Update sysmon_office_test_regadd.yml
This commit is contained in:
parent
df07d53fea
commit
70fb078a56
@ -1,7 +1,7 @@
|
||||
title: Office Application Startup - Office Test
|
||||
id: 3d27f6dd-1c74-4687-b4fa-ca849d128d1c
|
||||
status: experimental
|
||||
description: Detects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started
|
||||
description: Detects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed everytime an Office application is started
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1137/002/
|
||||
author: omkar72
|
||||
|
Loading…
Reference in New Issue
Block a user