Update win_grabbing_sensitive_hives_via_reg.yml

This commit is contained in:
Jonhnathan
2020-10-15 17:53:20 -03:00
committed by GitHub
parent 61a2f105c2
commit f44eb6345c
@@ -19,7 +19,7 @@ logsource:
product: windows
detection:
selection_1:
Image: '*\reg.exe'
Image|endswith: '\reg.exe'
CommandLine|contains:
- 'save'
- 'export'