diff --git a/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml b/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml index f3a28a27c..3a3763cc4 100644 --- a/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml +++ b/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml @@ -21,6 +21,10 @@ detection: fields: - CommandLine - ParentCommandLine +tags: + - attack.defense_Evasion + - attack.privelege_Escalation + - attack.t1088 falsepositives: - unknown level: critical