Update rules/windows/process_creation/proc_creation_win_credential_acquisition_registry_hive_dumping.yml

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
Gude5
2022-10-10 17:03:34 +02:00
committed by GitHub
parent 31717609cd
commit e70bced56e
@@ -22,5 +22,7 @@ detection:
CommandLine|contains:
- 'hklm\sam'
- 'hklm\security'
- 'HKEY_LOCAL_MACHINE\SAM'
- 'HKEY_LOCAL_MACHINE\SECURITY'
condition: all of selection_*
level: high