mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 00:02:11 +00:00
Create 121201-MITRE_TECHNIQUES_FROM_SYSMON_EVENT6.xml
This commit is contained in:
committed by
GitHub
parent
711e042885
commit
85e62f698b
@@ -0,0 +1,8 @@
|
||||
<group name="windows,sysmon,">
|
||||
<rule id="121201" level="3">
|
||||
<if_sid>61608</if_sid>
|
||||
<description>Driver loaded: $(win.eventdata.imageLoaded)</description>
|
||||
<options>no_full_log</options>
|
||||
<group>sysmon_event_6,</group>
|
||||
</rule>
|
||||
</group>
|
Reference in New Issue
Block a user