mirror of
				https://github.com/socfortress/Wazuh-Rules.git
				synced 2025-11-03 21:33:16 +00:00 
			
		
		
		
	Update MITRE_TECHNIQUES_FROM_SYSMON_EVENT13.xml
This commit is contained in:
		@@ -438,5 +438,16 @@
 | 
				
			|||||||
</mitre>
 | 
					</mitre>
 | 
				
			||||||
<options>no_full_log</options>
 | 
					<options>no_full_log</options>
 | 
				
			||||||
<group>sysmon_event_13,</group>
 | 
					<group>sysmon_event_13,</group>
 | 
				
			||||||
 | 
					</rule>
 | 
				
			||||||
 | 
					  <!-- Sysmon - Event 13: PsExec Detection -->
 | 
				
			||||||
 | 
					<rule id="112141" level="13">
 | 
				
			||||||
 | 
					<if_sid>61615</if_sid>
 | 
				
			||||||
 | 
					<field name="win.eventdata.TargetObject">\\\\PsExec\\\\EulaAccepted$</field>
 | 
				
			||||||
 | 
					<description>Sysmon - Event 13: RegistryEvent PsExec EulaAccepted Detected</description>
 | 
				
			||||||
 | 
					<mitre>
 | 
				
			||||||
 | 
					<id>T1047</id>
 | 
				
			||||||
 | 
					</mitre>
 | 
				
			||||||
 | 
					<options>no_full_log</options>
 | 
				
			||||||
 | 
					<group>sysmon_event_13,</group>
 | 
				
			||||||
</rule>
 | 
					</rule>
 | 
				
			||||||
</group>
 | 
					</group>
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user