Update proc_creation_win_mstsc.yml
This commit is contained in:
@@ -22,13 +22,13 @@ detection:
|
||||
- OriginalFileName: 'cmdkey.exe'
|
||||
selection_cmdkey_cli:
|
||||
CommandLine|contains|all:
|
||||
- '/g'
|
||||
- '/u'
|
||||
- '/p'
|
||||
- ' /g'
|
||||
- ' /u'
|
||||
- ' /p'
|
||||
condition: all of selection_mstsc* or all of selection_cmdkey*
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: medium
|
||||
tags:
|
||||
- attack.lateral_movement
|
||||
- attack.t1021.001
|
||||
- attack.t1021.001
|
||||
|
||||
Reference in New Issue
Block a user