mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 09:25:17 +00:00
Replace start of paths with placeholders
This commit is contained in:
parent
53f0261a62
commit
ff84852803
@ -17,8 +17,8 @@ detection:
|
||||
EventID: 4663
|
||||
AccessList|contains: '%%4416'
|
||||
ObjectName|endswith:
|
||||
- '\{641ECF7F-6AC4-4A63-BF85-DFDE140E9F89}\Machine\Preferences\Groups\Groups.xml'
|
||||
- '\Panther\Unattend.xml'
|
||||
- '\%POLICY_ID%\Machine\Preferences\Groups\Groups.xml'
|
||||
- '\%FOLDER_NAME%\Unattend.xml'
|
||||
condition: selection
|
||||
fields:
|
||||
- EventID
|
Loading…
Reference in New Issue
Block a user