mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update suspicious_reg_exe_process.yml
This commit is contained in:
@@ -3,7 +3,7 @@ id: a6b3ab4e-dd77-4213-95fa-fc94701995e0
|
||||
version: 4
|
||||
date: '2020-07-22'
|
||||
author: David Dorsey, Splunk
|
||||
type: TTP
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search looks for reg.exe being launched from a command prompt not
|
||||
|
||||
Reference in New Issue
Block a user