diff --git a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml index 89c68e99d5..867efa92ea 100644 --- a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml +++ b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml @@ -22,9 +22,11 @@ references: - https://devblogs.microsoft.com/oldnewthing/20080314-00/?p=23113 - https://blog.palantir.com/windows-privilege-abuse-auditing-detection-and-defense-3078a403d74e - https://atomicredteam.io/privilege-escalation/T1134.001/#atomic-test-2---%60sedebugprivilege%60-token-duplication +- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat tags: analytic_story: - Brute Ratel C4 + - AsyncRAT asset_type: Endpoint cis20: - CIS 3