Merge fixes for Rules
This commit is contained in:
@@ -3,7 +3,7 @@ id: 4720b7df-40c3-48fd-bbdf-fd4b3c464f0d
|
||||
description: Monitor the creation of a new key under 'TaskCache' when a new scheduled task is registered
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack..t1053
|
||||
- attack.t1053
|
||||
- attack.t1053.005
|
||||
date: 2021/06/18
|
||||
references:
|
||||
@@ -18,4 +18,4 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
TargetObject|contains: 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\'
|
||||
condition: selection
|
||||
condition: selection
|
||||
|
||||
Reference in New Issue
Block a user