Merge branch 'redcannary_20230113' of github.com:frack113/sigma into redcannary_20230113
This commit is contained in:
@@ -24,7 +24,7 @@ detection:
|
||||
CommandLine|contains|all:
|
||||
- '\system\currentcontrolset\control\lsa'
|
||||
- 'DisableRestrictedAdmin'
|
||||
- ' 0'
|
||||
- ' 1'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
|
||||
Reference in New Issue
Block a user