Skip to content

Commit

Permalink
Update win_security_svcctl_remote_service.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
GtUGtHGtNDtEUaE authored Aug 1, 2024
1 parent 666d2bb commit f5cb339
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ references:
- https://web.archive.org/web/20230329155141/https://blog.menasec.net/2019/03/threat-hunting-26-remote-windows.html
author: Samir Bousseaden
date: 2019/04/03
modified: 2022/08/11
modified: 2024/08/01
tags:
- attack.lateral_movement
- attack.persistence
Expand All @@ -20,7 +20,7 @@ detection:
EventID: 5145
ShareName: '\\\\\*\\IPC$' # looking for the string \\*\IPC$
RelativeTargetName: svcctl
Accesses|contains: 'WriteData'
AccessList|contains: 'WriteData'
condition: selection
falsepositives:
- Unknown
Expand Down

0 comments on commit f5cb339

Please sign in to comment.