From 324b58bf12dc2d0b60e490c13e0a12398358184c Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Thu, 1 Sep 2022 15:40:48 +0200 Subject: [PATCH] Update windows_service_deletion_in_registry.yml --- detections/endpoint/windows_service_deletion_in_registry.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_service_deletion_in_registry.yml b/detections/endpoint/windows_service_deletion_in_registry.yml index e2e3904e08..9e2cb922ba 100644 --- a/detections/endpoint/windows_service_deletion_in_registry.yml +++ b/detections/endpoint/windows_service_deletion_in_registry.yml @@ -39,7 +39,7 @@ tags: - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/brute_ratel/service_deletion/sysmon.log - impact: 70 + impact: 80 kill_chain_phases: - Exploitation message: a service registry $Registry.registry_path$ was deleted in $Registry.dest$