Skip to content

Commit 8ce18be

Browse files
committed
1 parent d577872 commit 8ce18be

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

rules/windows/builtin/security/win_security_service_install_remote_access_software.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ references:
99
- https://redcanary.com/blog/misbehaving-rats/
1010
author: Connor Martin, Nasreddine Bencherchali (Nextron Systems)
1111
date: 2022/12/23
12-
modified: 2023/06/22
12+
modified: 2023/11/15
1313
tags:
1414
- attack.persistence
1515
- attack.t1543.003
@@ -21,7 +21,7 @@ logsource:
2121
detection:
2222
selection:
2323
EventID: 4697
24-
ServiceFileName|contains:
24+
ServiceName|contains:
2525
# Based on https://github.com/SigmaHQ/sigma/pull/2841
2626
- 'AmmyyAdmin' # https://www.ammyy.com/en/
2727
- 'Atera'

0 commit comments

Comments
 (0)