mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
secondbatchwinprivesctaghermeticwiper
This commit is contained in:
@@ -39,6 +39,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
confidence: 70
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -28,6 +28,7 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 8
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
- Suspicious Windows Registry Activities
|
||||
- Cloud Federated Credential Abuse
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
cis20:
|
||||
- CIS 8
|
||||
confidence: 95
|
||||
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
confidence: 50
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
confidence: 90
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -28,6 +28,7 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 5
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
context:
|
||||
|
||||
Reference in New Issue
Block a user