Bugfix: Minor fix cause Sysmon uses SID as Software key
This commit is contained in:
@@ -9,8 +9,9 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 13
|
||||
TargetObject: 'HKEY_USERS\Software\Classes\exefile\shell\runas\command\isolatedCommand'
|
||||
TargetObject: 'HKEY_USERS\*\Classes\exefile\shell\runas\command\isolatedCommand'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- unknown
|
||||
level: high
|
||||
|
||||
|
||||
Reference in New Issue
Block a user