Update rules/windows/process_creation/proc_creation_win_credential_acquisition_registry_hive_dumping.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
+2
@@ -22,5 +22,7 @@ detection:
|
||||
CommandLine|contains:
|
||||
- 'hklm\sam'
|
||||
- 'hklm\security'
|
||||
- 'HKEY_LOCAL_MACHINE\SAM'
|
||||
- 'HKEY_LOCAL_MACHINE\SECURITY'
|
||||
condition: all of selection_*
|
||||
level: high
|
||||
|
||||
Reference in New Issue
Block a user