fix issues with wrong tagging

This commit is contained in:
Yugoslavskiy Daniil
2019-12-15 00:17:22 +01:00
parent 9a511e5e62
commit d19df2e4f7
4 changed files with 4 additions and 4 deletions
@@ -8,7 +8,7 @@ author: Endgame, JHasenbusch (adapted to sigma for oscd.community)
date: 2018/10/30
modified: 2019/11/11
tags:
- attack.persistance
- attack.persistence
- attack.credential_access
- attack.t1136
logsource:
@@ -7,7 +7,7 @@ references:
- https://azure.microsoft.com/en-ca/blog/detecting-in-memory-attacks-with-sysmon-and-azure-security-center/
tags:
- attack.privilege_escalation
- attack.T1055
- attack.t1055
logsource:
product: windows
service: sysmon
@@ -10,7 +10,7 @@ references:
- https://medium.com/@fsx30/bypass-edrs-memory-protection-introduction-to-hooking-2efb21acffd6
tags:
- attack.credential_access
- attack.T1003
- attack.t1003
logsource:
product: windows
service: sysmon
@@ -14,7 +14,7 @@ logsource:
service: sysmon
tags:
- attack.privilege_escalation
- attack.T1055
- attack.t1055
detection:
selection:
EventID: 8