Update sysmon_uac_bypass_eventvwr.yml
This commit is contained in:
@@ -21,6 +21,10 @@ detection:
|
||||
fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
tags:
|
||||
- attack.defense_Evasion
|
||||
- attack.privelege_Escalation
|
||||
- attack.t1088
|
||||
falsepositives:
|
||||
- unknown
|
||||
level: critical
|
||||
|
||||
Reference in New Issue
Block a user