mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Removed unnecessary '1 of them' in condition
This commit is contained in:
parent
8d819cfeea
commit
cd3cdc9451
@ -15,7 +15,7 @@ detection:
|
||||
selection:
|
||||
EventID: 4688
|
||||
ProcessCommandLine: 'C:\Windows\PSEXESVC.exe'
|
||||
condition: 1 of them
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Administrative activity
|
||||
level: low
|
@ -15,7 +15,7 @@ detection:
|
||||
- '*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\\*\ReportingMode'
|
||||
- '*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\\*\MonitorProcess'
|
||||
EventType: 'SetValue'
|
||||
condition: 1 of them
|
||||
condition: selection_reg1
|
||||
tags:
|
||||
- attack.privilege_escalation
|
||||
- attack.persistence
|
||||
|
Loading…
Reference in New Issue
Block a user