Files
sigma-rules/rules/windows
Samirbous 475d67f1e8 [Rule Tuning] Potential Remote Credential Access via Registry (#2203)
* [Rule Tuning] Potential Remote Credential Access via Registry

Excluding some noisy FPs by file.path (user and machine hives std paths) and event.action (scoped to logged-in)

* Update credential_access_remote_sam_secretsdump.toml

(cherry picked from commit 049fbf7979)
2022-08-01 15:50:38 +00:00
..