diff --git a/Windows_Sysmon/MITRE_TECHNIQUES_FROM_SYSMON_EVENT13.xml b/Windows_Sysmon/MITRE_TECHNIQUES_FROM_SYSMON_EVENT13.xml index 64dbbb6..afce66a 100644 --- a/Windows_Sysmon/MITRE_TECHNIQUES_FROM_SYSMON_EVENT13.xml +++ b/Windows_Sysmon/MITRE_TECHNIQUES_FROM_SYSMON_EVENT13.xml @@ -438,5 +438,16 @@ no_full_log sysmon_event_13, + + + +61615 +\\\\PsExec\\\\EulaAccepted$ +Sysmon - Event 13: RegistryEvent PsExec EulaAccepted Detected + +T1047 + +no_full_log +sysmon_event_13,