Update sysmon_susp_lsass_dll_load.yml

This commit is contained in:
Jonhnathan 2020-10-15 20:08:12 -03:00 committed by GitHub
parent 17ade8e5f5
commit b55b78c42d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -13,9 +13,9 @@ logsource:
product: windows
detection:
selection:
TargetObject:
- '*\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt*'
- '*\CurrentControlSet\Services\NTDS\LsaDbExtPt*'
TargetObject|contains:
- '\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt'
- '\CurrentControlSet\Services\NTDS\LsaDbExtPt'
condition: selection
tags:
- attack.execution