Merge PR #5631 from @ david-syk - remove trailing slash

update: RestrictedAdminMode Registry Value Tampering - ProcCreation - remove trailing slash

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <monsteroffire2@gmail.com>
This commit is contained in:
david-syk
2025-09-22 12:15:35 +02:00
committed by GitHub
parent fe015f3c24
commit d2dcc579e8
@@ -14,7 +14,7 @@ references:
- https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/
author: frack113
date: 2023-01-13
modified: 2023-12-15
modified: 2025-08-28
tags:
- attack.defense-evasion
- attack.t1112
@@ -24,7 +24,7 @@ logsource:
detection:
selection:
CommandLine|contains|all:
- '\System\CurrentControlSet\Control\Lsa\'
- '\System\CurrentControlSet\Control\Lsa'
- 'DisableRestrictedAdmin'
condition: selection
falsepositives: