mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update wsreset_uac_bypass.yml
This commit is contained in:
@@ -52,9 +52,9 @@ tags:
|
||||
- Stage:Privilege Escalation
|
||||
- Stage:Defense Evasion
|
||||
- Scope:Incoming
|
||||
message: Suspicious modification of registry $Registry.registry_path$ with possible payload path $Registry.registry_value_name$ in $Registry.dest$
|
||||
message: Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$
|
||||
observable:
|
||||
- name: Registry.dest
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
|
||||
Reference in New Issue
Block a user