Files
blue-team-tools/rules/windows/builtin/application/win_builtin_remove_application.yml
T
2022-01-28 16:12:38 +01:00

23 lines
491 B
YAML

title: An Application Is Uninstall
id: 570ae5ec-33dc-427c-b815-db86228ad43e
status: experimental
description: An application have been remove check if it is a critical
author: frack113
date: 2022/01/28
logsource:
product: windows
service: application
detection:
selection:
Provider_Name: 'MsiInstaller'
EventID:
- 11724
- 1034
condition: selection
falsepositives:
- Unknown
level: low
tags:
- attack.impact
- attack.t1489