mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
95e3b87faf
* "Startup/Logon Script added to Group Policy Object" Initial Rule * Change severity * nest non-ecs schema and move logs-system to winlogbeat * format query and remove quotes * Update rules/windows/privilege_escalation_group_policy_iniscript.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Add rule_ids and false_positives instance Co-authored-by: brokensound77 <brokensound77@users.noreply.github.com>