mirror of
https://github.com/keyboardcrunch/SentinelOne-ATTACK-Queries
synced 2026-06-10 18:11:21 +00:00
Update and rename queries.md to PrivilegeEscalation.md
This commit is contained in:
@@ -1,4 +1,3 @@
|
|||||||
# Windows Atomic Tests by ATT&CK Tactic & Technique
|
|
||||||
## Privilege Escalation
|
## Privilege Escalation
|
||||||
|
|
||||||
### T1053.002 AT Scheduled Task
|
### T1053.002 AT Scheduled Task
|
||||||
@@ -222,8 +221,3 @@ Detects Winlogon Helper Dll changes through Registry MetadataIndicator item, as
|
|||||||
IndicatorMetadata In Contains Anycase ("Microsoft\Windows NT\CurrentVersion\Winlogon","Microsoft\Windows NT\CurrentVersion\Winlogon\Notify") AND IndicatorMetadata In Contains Anycase ("logon","Userinit","Shell") AND IndicatorMetadata Does Not ContainCIS "WINDOWS\system32\userinit.exe"
|
IndicatorMetadata In Contains Anycase ("Microsoft\Windows NT\CurrentVersion\Winlogon","Microsoft\Windows NT\CurrentVersion\Winlogon\Notify") AND IndicatorMetadata In Contains Anycase ("logon","Userinit","Shell") AND IndicatorMetadata Does Not ContainCIS "WINDOWS\system32\userinit.exe"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
## Defense Evasion
|
|
||||||
### T1055.004 Asynchronous Procedure Call
|
|
||||||
Atomics: [T1055.004]()
|
|
||||||
|
|
||||||
Reference in New Issue
Block a user