Removed redundant attribute from rule

EventID 4657 already implies the modification.
This commit is contained in:
Thomas Patzke 2018-06-02 22:37:26 +02:00
parent e72c0d5de4
commit df6ad82770

View File

@ -32,7 +32,6 @@ logsource:
detection: detection:
selection2: selection2:
EventID: 4657 EventID: 4657
OperationType: 'Existing registry value modified'
ObjectName: '\REGISTRY\MACHINE\SYSTEM\*ControlSet*\Control\Lsa' ObjectName: '\REGISTRY\MACHINE\SYSTEM\*ControlSet*\Control\Lsa'
ObjectValueName: ObjectValueName:
- 'LmCompatibilityLevel' - 'LmCompatibilityLevel'