Update win_wmi_persistence.yml

Removed sequence of EIDs in Windows Security section.
This commit is contained in:
GlebSukhodolskiy
2021-01-06 16:50:28 +03:00
committed by GitHub
parent 198add2229
commit da5ec4e952
+1 -6
View File
@@ -38,13 +38,8 @@ logsource:
product: windows
service: security
detection:
network_logon:
EventID: 4624
LogonType: 3
privileges_assigned:
EventID: 4672
wmi_subscription:
EventID: 4662
ObjectType: 'WMI Namespace'
ObjectName|contains: 'subscription'
condition: network_logon and privileges_assigned and wmi_subscription
condition: wmi_subscription