From 415ced00237a42ebd829ea1c983c7163b4c9d119 Mon Sep 17 00:00:00 2001 From: Hasan Date: Tue, 15 Jun 2021 19:07:50 +0500 Subject: [PATCH] Corrected MITRE reference tag --- rules/windows/registry_event/sysmon_taskcache_entry.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/windows/registry_event/sysmon_taskcache_entry.yml b/rules/windows/registry_event/sysmon_taskcache_entry.yml index 4e7ec813b..e1659704c 100644 --- a/rules/windows/registry_event/sysmon_taskcache_entry.yml +++ b/rules/windows/registry_event/sysmon_taskcache_entry.yml @@ -3,7 +3,7 @@ id: 4720b7df-40c3-48fd-bbdf-fd4b3c464f0d description: Monitor the creation of a new key under 'TaskCache' when a new scheduled task is registered tags: - attack.persistence - - attack..t1053 + - attack.t1053 - attack.t1053.005 date: 2021/06/18 references: @@ -18,4 +18,4 @@ logsource: detection: selection: TargetObject|contains: '*SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\*' - condition: selection \ No newline at end of file + condition: selection