Update proc_creation_win_user_discovery_get_aduser.yml
This commit is contained in:
@@ -24,7 +24,7 @@ detection:
|
||||
condition: all of selection_*
|
||||
falsepositives:
|
||||
- Legitimate admin scripts may use the same technique, it's better to exclude specific computers or users who execute these commands or scripts often
|
||||
level: high
|
||||
level: medium
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1033
|
||||
|
||||
Reference in New Issue
Block a user