From 21bee17ffdfd29ef4d1b5923df275ee7f0683dd8 Mon Sep 17 00:00:00 2001 From: Lurkkeli Date: Tue, 7 Aug 2018 08:07:49 +0200 Subject: [PATCH] Update sysmon_uac_bypass_eventvwr.yml --- rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml b/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml index f3a28a27c..3a3763cc4 100644 --- a/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml +++ b/rules/windows/sysmon/sysmon_uac_bypass_eventvwr.yml @@ -21,6 +21,10 @@ detection: fields: - CommandLine - ParentCommandLine +tags: + - attack.defense_Evasion + - attack.privelege_Escalation + - attack.t1088 falsepositives: - unknown level: critical