SigmaHQ/rules/windows/malware
megan201296 eb8a0636c5
Update win_mal_ursnif.yml
After @thomaspatzke changed to HKU, I did some reading. HKU is for HKEY_User, not HKEY_Current_User (what this threat is tied to. However, he was correct that HKCU does not exist as a prefix for sysmon (see the notes section under event id 13 here: https://github.com/SwiftOnSecurity/sysmon-config/blob/master/sysmonconfig-export.xml). Changed to ignore the key name, confirmed that the key is still uniique.
2019-04-14 11:51:13 -05:00
..
av_exploiting.yml adding MPreter as McAfee classifies it 2019-02-22 15:22:10 +11:00
av_password_dumper.yml ATT&CK tagging QA 2018-09-20 12:44:44 +02:00
av_relevant_files.yml Escaped '\*' to '\\*' where required 2019-02-03 00:24:57 +01:00
av_webshell.yml ATT&CK tagging QA 2018-09-20 12:44:44 +02:00
win_mal_ursnif.yml Update win_mal_ursnif.yml 2019-04-14 11:51:13 -05:00