Update win_grabbing_sensitive_hives_via_reg.yml
This commit is contained in:
@@ -19,7 +19,7 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection_1:
|
||||
Image: '*\reg.exe'
|
||||
Image|endswith: '\reg.exe'
|
||||
CommandLine|contains:
|
||||
- 'save'
|
||||
- 'export'
|
||||
|
||||
Reference in New Issue
Block a user