Update driver_load_susp_temp_use.yml

This commit is contained in:
Nasreddine Bencherchali
2022-07-28 12:40:30 +01:00
parent d4c0c79ee4
commit 0d8dba5200
@@ -6,16 +6,16 @@ author: Florian Roth
date: 2017/02/12
modified: 2021/11/27
logsource:
category: driver_load
product: windows
category: driver_load
product: windows
detection:
selection:
ImageLoaded|contains: '\Temp\'
condition: selection
selection:
ImageLoaded|contains: '\Temp\'
condition: selection
falsepositives:
- There is a relevant set of false positives depending on applications in the environment
- There is a relevant set of false positives depending on applications in the environment
level: high
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1543.003
- attack.persistence
- attack.privilege_escalation
- attack.t1543.003