Skip to content

[Rule Tuning] Tuning of 3 existing windows rules, details below #122

@Samirbous

Description

@Samirbous

windows_priv_escalation_via_accessibility_features.toml (needs a not condition )
windows_register_server_program_connecting_to_the_internet.toml (add regasm.exe)
windows_net_command_system_account.toml (added whoami as well both rare with System NT Authority)

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions