From 71c2be5507883dd3ddcfe8198669feea877d16db Mon Sep 17 00:00:00 2001 From: Qasim Qlf Date: Fri, 3 Feb 2023 15:33:26 +0500 Subject: [PATCH] Update proc_creation_win_whoami_priv.yml --- .../process_creation/proc_creation_win_whoami_priv.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/windows/process_creation/proc_creation_win_whoami_priv.yml b/rules/windows/process_creation/proc_creation_win_whoami_priv.yml index d4e68ae09..e382982c3 100644 --- a/rules/windows/process_creation/proc_creation_win_whoami_priv.yml +++ b/rules/windows/process_creation/proc_creation_win_whoami_priv.yml @@ -6,7 +6,7 @@ references: - https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/whoami author: Florian Roth (Nextron Systems) date: 2021/05/05 -modified: 2022/05/13 +modified: 2023/02/03 tags: - attack.privilege_escalation - attack.discovery @@ -20,7 +20,7 @@ detection: - OriginalFileName: 'whoami.exe' selection_cli: CommandLine|contains: '/priv' - condition: all of selection* + condition: all of selection_* falsepositives: - Administrative activity (rare lookups on current privileges) level: high