mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update sysmon_susp_lsass_dll_load.yml
This commit is contained in:
parent
17ade8e5f5
commit
b55b78c42d
@ -13,9 +13,9 @@ logsource:
|
|||||||
product: windows
|
product: windows
|
||||||
detection:
|
detection:
|
||||||
selection:
|
selection:
|
||||||
TargetObject:
|
TargetObject|contains:
|
||||||
- '*\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt*'
|
- '\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt'
|
||||||
- '*\CurrentControlSet\Services\NTDS\LsaDbExtPt*'
|
- '\CurrentControlSet\Services\NTDS\LsaDbExtPt'
|
||||||
condition: selection
|
condition: selection
|
||||||
tags:
|
tags:
|
||||||
- attack.execution
|
- attack.execution
|
||||||
|
Loading…
Reference in New Issue
Block a user