f48144c6b3
* [New Rule] Registry Hive File Creation via SMB Identifies the creation or modification of a medium size registry hive file via the SMB protocol : * Update credential_access_moving_registry_hive_via_smb.toml * Update etc/non-ecs-schema.json Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>