Update sysmon_abusing_debug_privilege.yml
NT AUTHORITY\SYSTEM
This commit is contained in:
@@ -28,7 +28,7 @@ detection:
|
||||
- '\powershell.exe'
|
||||
- '\cmd.exe'
|
||||
selection3:
|
||||
User: 'NT AUTHORITY\\SYSTEM'
|
||||
User: 'NT AUTHORITY\SYSTEM'
|
||||
filter:
|
||||
CommandLine|contains|all:
|
||||
- ' route ADD '
|
||||
|
||||
Reference in New Issue
Block a user