fix: FP found in testing environment
This commit is contained in:
@@ -3,7 +3,7 @@ id: 2f78da12-f7c7-430b-8b19-a28f269b77a3
|
||||
description: Detects tempering with the "Enabled" registry key in order to disable windows logging of a windows event channel
|
||||
author: frack113, Nasreddine Bencherchali
|
||||
date: 2022/07/04
|
||||
modified: 2022/09/08
|
||||
modified: 2022/09/19
|
||||
status: experimental
|
||||
references:
|
||||
- https://twitter.com/WhichbufferArda/status/1543900539280293889
|
||||
@@ -27,6 +27,7 @@ detection:
|
||||
TargetObject|contains:
|
||||
- '\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-FileInfoMinifilter'
|
||||
- '\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ASN1\'
|
||||
- '\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-AppCompat\'
|
||||
filter_empty: # This filter is related to aurora. Should be removed when fix is deployed. # TODO: Remove later
|
||||
Image:
|
||||
- ''
|
||||
|
||||
Reference in New Issue
Block a user