Skip to content

Commit bb55038

Browse files
Apply suggestions from code review
1 parent 541f1c7 commit bb55038

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

rules/windows/process_creation/proc_creation_win_credential_guard_registry_tampering.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,8 +37,8 @@ detection:
3737
- 'si ' # SetItem Alias
3838
selection_key_base:
3939
CommandLine|contains:
40-
- 'CurrentControlSet\Control\DeviceGuard'
41-
- 'CurrentControlSet\Control\LSA'
40+
- '\Control\DeviceGuard'
41+
- '\Control\LSA'
4242
- 'Software\Policies\Microsoft\Windows\DeviceGuard'
4343
selection_key_specific:
4444
CommandLine|contains:

rules/windows/registry/registry_delete/registry_delete_disable_credential_guard.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
title: Windows Credential Guard Related Registry Values Deleted
1+
title: Windows Credential Guard Related Registry Value Deleted - Registry
22
id: d645ef86-2396-48a1-a2b6-b629ca3f57ff
33
related:
44
- id: c629cc9b-8ddf-4282-9f10-6934ce3ea1ee

0 commit comments

Comments
 (0)