SigmaHQ/wazuh/rules/sigma_win_wsreset_uac_bypass.yml
joker2013 50379800f2 123
2020-12-03 01:43:30 +03:00

16 lines
351 B
YAML

alert:
- debug
description: Detects a method that uses Wsreset.exe tool that can be used to reset the Windows Store to bypass UAC
filter:
- query:
query_string:
query: data.win.eventdata.parentImage.keyword:(*\\WSreset.exe)
index: wazuh-alerts-3.x-*
name: bdc8918e-a1d5-49d1-9db7-ea0fd91aa2ae_0
priority: 2
realert:
minutes: 0
type: any