mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-27 01:43:32 +00:00
Update MITRE_TECHNIQUES_FROM_SYSMON_EVENT13.xml
This commit is contained in:
@@ -438,5 +438,16 @@
|
|||||||
</mitre>
|
</mitre>
|
||||||
<options>no_full_log</options>
|
<options>no_full_log</options>
|
||||||
<group>sysmon_event_13,</group>
|
<group>sysmon_event_13,</group>
|
||||||
|
</rule>
|
||||||
|
<!-- Sysmon - Event 13: PsExec Detection -->
|
||||||
|
<rule id="112141" level="13">
|
||||||
|
<if_sid>61615</if_sid>
|
||||||
|
<field name="win.eventdata.TargetObject">\\\\PsExec\\\\EulaAccepted$</field>
|
||||||
|
<description>Sysmon - Event 13: RegistryEvent PsExec EulaAccepted Detected</description>
|
||||||
|
<mitre>
|
||||||
|
<id>T1047</id>
|
||||||
|
</mitre>
|
||||||
|
<options>no_full_log</options>
|
||||||
|
<group>sysmon_event_13,</group>
|
||||||
</rule>
|
</rule>
|
||||||
</group>
|
</group>
|
||||||
|
|||||||
Reference in New Issue
Block a user