Merge branch 'TR2850_RBA_PrivEsc' of github.com:splunk/security_content into TR2850_RBA_PrivEsc

This commit is contained in:
mvelazco
2023-05-23 17:26:30 -04:00
6 changed files with 12 additions and 0 deletions
@@ -35,6 +35,8 @@ tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
atomic_guid:
- 12e03af7-79f9-4f95-af48-d3f12f28a260
confidence: 50
impact: 50
message: A registry modification in Windows auto update notification on $dest$
@@ -33,6 +33,8 @@ tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
atomic_guid:
- 12e03af7-79f9-4f95-af48-d3f12f28a260
confidence: 70
impact: 70
message: A registry modification to disable Windows Defender notification on $dest$
@@ -37,6 +37,8 @@ tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
atomic_guid:
- 12e03af7-79f9-4f95-af48-d3f12f28a260
confidence: 50
impact: 50
message: a registry modification in Windows auto update configuration in $dest$
@@ -35,6 +35,8 @@ tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
atomic_guid:
- 12e03af7-79f9-4f95-af48-d3f12f28a260
confidence: 30
impact: 30
message: A registry modification in Windows auto update configuration on $dest$
@@ -35,6 +35,8 @@ tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
atomic_guid:
- 12e03af7-79f9-4f95-af48-d3f12f28a260
confidence: 70
impact: 70
message: A registry modification in Windows auto update configuration on $dest$
@@ -33,6 +33,8 @@ tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
atomic_guid:
- 12e03af7-79f9-4f95-af48-d3f12f28a260
confidence: 70
impact: 70
message: A registry modification to tamper Windows Defender protection on $dest$