Update sysmon_logon_scripts_userinitmprlogonscript_reg.yml
This commit is contained in:
@@ -17,9 +17,9 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
create_keywords_reg:
|
||||
TargetObject: '*UserInitMprLogonScript*'
|
||||
TargetObject|contains: 'UserInitMprLogonScript'
|
||||
condition: create_keywords_reg
|
||||
falsepositives:
|
||||
- exclude legitimate logon scripts
|
||||
- penetration tests, red teaming
|
||||
level: high
|
||||
level: high
|
||||
|
||||
Reference in New Issue
Block a user