mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
detections/endpoint/disabling_systemrestore_in_registry.yml
This commit is contained in:
@@ -51,8 +51,7 @@ tags:
|
||||
message: The Windows registry was modified to disable system restore on $dest$ by
|
||||
$user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
- T1490
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
Reference in New Issue
Block a user