Update credential_access_mod_wdigest_security_provider.toml (#1751)
(cherry picked from commit 40095d95bf)
This commit is contained in:
committed by
github-actions[bot]
parent
d7011f7128
commit
a884d8a237
@@ -1,7 +1,7 @@
|
||||
[metadata]
|
||||
creation_date = "2021/01/19"
|
||||
maturity = "production"
|
||||
updated_date = "2021/03/03"
|
||||
updated_date = "2022/02/03"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -28,9 +28,10 @@ timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
registry where event.type in ("creation", "change") and
|
||||
registry.path:"HKLM\\SYSTEM\\*ControlSet*\\Control\\SecurityProviders\\WDigest\\UseLogonCredential" and
|
||||
registry.data.strings:"1"
|
||||
registry where event.type : ("creation", "change") and
|
||||
registry.path :
|
||||
"HKLM\\SYSTEM\\*ControlSet*\\Control\\SecurityProviders\\WDigest\\UseLogonCredential"
|
||||
and registry.data.strings : ("1", "0x00000001")
|
||||
'''
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user