From 0bd33e994408cfdb90c2013b194ca7eeb698e2b2 Mon Sep 17 00:00:00 2001 From: phantinuss <79651203+phantinuss@users.noreply.github.com> Date: Wed, 27 Jul 2022 11:13:48 +0200 Subject: [PATCH] add UACMe reference Id --- .../proc_creation_win_tools_uac_bypass_computerdefaults.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/process_creation/proc_creation_win_tools_uac_bypass_computerdefaults.yml b/rules/windows/process_creation/proc_creation_win_tools_uac_bypass_computerdefaults.yml index fe48e2e45..19e5917e1 100644 --- a/rules/windows/process_creation/proc_creation_win_tools_uac_bypass_computerdefaults.yml +++ b/rules/windows/process_creation/proc_creation_win_tools_uac_bypass_computerdefaults.yml @@ -1,6 +1,6 @@ title: UAC Bypass Tools Using ComputerDefaults id: 3c05e90d-7eba-4324-9972-5d7f711a60a8 -description: Detects tools such as UACMe used to bypass UAC with computerdefaults.exe +description: Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59) author: Christian Burkard date: 2021/08/31 status: experimental