diff --git a/rules/windows/process_creation/win_net_user_add.yml b/rules/windows/process_creation/win_net_user_add.yml index 951600fd2..7dbef3b56 100644 --- a/rules/windows/process_creation/win_net_user_add.yml +++ b/rules/windows/process_creation/win_net_user_add.yml @@ -5,7 +5,7 @@ references: - https://eqllib.readthedocs.io/en/latest/analytics/014c3f51-89c6-40f1-ac9c-5688f26090ab.html - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1136/T1136.yaml author: Endgame, JHasenbusch (adapted to sigma for oscd.community) -date: 2018/30/11 +date: 2018/10/30 modified: 2019/11/11 tags: - attack.persistance