Files
Patrick Bareiss f74a0fe273 successful tested
2020-07-28 11:14:34 +02:00

8 lines
247 B
YAML

name: Modify Registry
detections:
- name: Suspicious Reg exe Process
pass_condition: '| stats count | where count > 5'
description: Test Modify Registry detections
target: attack-range-windows-domain-controller
simulation_technique: 'T1112'