Imports Registry Key From an ADS (0b80ade5-6997-4b1d-99a1-71701778ea61)
Detects the import of a alternate datastream to the registry with regedit.exe.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Imports Registry Key From an ADS (0b80ade5-6997-4b1d-99a1-71701778ea61) | Sigma-Rules | Modify Registry - T1112 (57340c81-c025-4189-8fa0-fc7ede51bae4) | Attack Pattern | 1 |