Sagan critical stable other
[WINDOWS-SECURITY] Disable Windows Defender Logging
[WINDOWS-SECURITY] Disable Windows Defender Logging
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Disable Windows Defender Logging"; program:Security
| *Sysmon*; event_id:1,4688; meta_content:"\Control\WMI\Autologger\%sagan%",DefenderApiLogger,DefenderAuditLogger; meta_nocase; content:"REG_DWORD /d
| 22
| 0
| 22
| "; reference:url,https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/; classtype:trojan-activity; sid:5015079; rev:1; metadata:deployment Endpoint, created_at 2024_08_20, updated_at 2024_08_20, mitre_tactic_id TA0008, mitre_technique_id T1071;) Field Validations
Loading…
Comments (0)
Loading comments...