Update proc_creation_win_mstsc.yml

This commit is contained in:
frack113
2022-06-12 17:52:37 +02:00
committed by GitHub
parent b0730c613b
commit fb0618795f
@@ -22,13 +22,13 @@ detection:
- OriginalFileName: 'cmdkey.exe'
selection_cmdkey_cli:
CommandLine|contains|all:
- '/g'
- '/u'
- '/p'
- ' /g'
- ' /u'
- ' /p'
condition: all of selection_mstsc* or all of selection_cmdkey*
falsepositives:
- Unknown
level: medium
tags:
- attack.lateral_movement
- attack.t1021.001
- attack.t1021.001