Update sysmon_susp_lsass_dll_load.yml

This commit is contained in:
Jonhnathan 2020-10-15 20:08:12 -03:00 committed by GitHub
parent 17ade8e5f5
commit b55b78c42d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -13,9 +13,9 @@ logsource:
product: windows product: windows
detection: detection:
selection: selection:
TargetObject: TargetObject|contains:
- '*\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt*' - '\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt'
- '*\CurrentControlSet\Services\NTDS\LsaDbExtPt*' - '\CurrentControlSet\Services\NTDS\LsaDbExtPt'
condition: selection condition: selection
tags: tags:
- attack.execution - attack.execution