Skip to content

Commit e1c5444

Browse files
authored
Update README.md
1 parent 5847ca9 commit e1c5444

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

README.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,9 @@ details: Adversaries can use built-in library comsvcs.dll to dump credentials on
5656
author: SOC Prime Team
5757
severity: high
5858
date: 2020-05-24
59-
mitre-attack: t1003.001
59+
mitre-attack:
60+
- t1003.001
61+
- t1136.003
6062
detection:
6163
language: splunk-spl-query # elastic-lucene-query, logscale-lql-query, mde-kql-query
6264
body: index=* ((((process="*comsvcs*") AND (process="*MiniDump*")) OR ((process="*comsvcs*") AND (process="*#24*"))) OR ((process="*comsvcs*") AND (process="*full*")))

0 commit comments

Comments
 (0)