WMI persistence modified

This commit is contained in:
Florian Roth
2017-08-24 18:26:58 +02:00
parent 783722e0b2
commit f46e86fbb1
+2 -1
View File
@@ -1,6 +1,6 @@
title: WMI Persistence
status: experimental
description: Detects suspicious WMI event filter and command line event consumer based on event id 5861 (Windows 10)
description: Detects suspicious WMI event filter and command line event consumer based on event id 5861 (Windows 10, 2012 and higher)
author: Florian Roth
reference: https://twitter.com/mattifestation/status/899646620148539397
logsource:
@@ -17,3 +17,4 @@ detection:
falsepositives:
- Unknown (data set is too small; further testing needed)
level: high