Skip to content

Commit

Permalink
Updated after successful CICD run 06/21/2023 13:04:13 UTC
Browse files Browse the repository at this point in the history
  • Loading branch information
Azure Pipeline committed Jun 21, 2023
1 parent d174fe8 commit 7c69adc
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion sysmonconfig-mde-augment.xml
Original file line number Diff line number Diff line change
Expand Up @@ -144,7 +144,7 @@
<Rule name="File Permissions Modification" groupRelation="or">
<OriginalFileName name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="is">takeown.exe</OriginalFileName>
<Image name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="image">forfiles.exe</Image>
<OriginalFileName name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="contains any">icacls.exe;cacls.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="contains any">icacls.exe;cacls.exe;xcacls.exe</OriginalFileName>
</Rule>
<Rule name="Access Token Manipulation" groupRelation="or">
<OriginalFileName name="technique_id=T1134,technique_name=Access Token Manipulation" condition="is">runas.exe</OriginalFileName>
Expand Down
2 changes: 1 addition & 1 deletion sysmonconfig.xml
Original file line number Diff line number Diff line change
Expand Up @@ -139,7 +139,7 @@
<Rule name="File Permissions Modification" groupRelation="or">
<OriginalFileName name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="is">takeown.exe</OriginalFileName>
<Image name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="image">forfiles.exe</Image>
<OriginalFileName name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="contains any">icacls.exe;cacls.exe</OriginalFileName>
<OriginalFileName name="technique_id=T1222.001,technique_name=File Permissions Modification" condition="contains any">icacls.exe;cacls.exe;xcacls.exe</OriginalFileName>
</Rule>
<Rule name="Access Token Manipulation" groupRelation="or">
<OriginalFileName name="technique_id=T1134,technique_name=Access Token Manipulation" condition="is">runas.exe</OriginalFileName>
Expand Down

0 comments on commit 7c69adc

Please sign in to comment.