Hayabusa high test sigma
UAC Bypass via Event Viewer
Detects UAC bypass method using Windows event viewer
Detection Logic
{
"registry_set": {
"EventID": 13,
"Channel": "Microsoft-Windows-Sysmon/Operational"
},
"selection": {
"TargetObject
| endswith": "\\mscfile\\shell\\open\\command"
},
"condition": "registry_set and selection"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...