Bugfix: Minor fix cause Sysmon uses SID as Software key

This commit is contained in:
Florian Roth
2017-03-21 10:44:53 +01:00
parent b1da8c5b32
commit 3bfa9ed121
@@ -9,8 +9,9 @@ logsource:
detection:
selection:
EventID: 13
TargetObject: 'HKEY_USERS\Software\Classes\exefile\shell\runas\command\isolatedCommand'
TargetObject: 'HKEY_USERS\*\Classes\exefile\shell\runas\command\isolatedCommand'
condition: selection
falsepositives:
- unknown
level: high