Sysmon Configuration Modification (1f2b5353-573f-4880-8e33-7d04dcf97744)
Detects when an attacker tries to hide from Sysmon by disabling or stopping it
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Sysmon Configuration Modification (1f2b5353-573f-4880-8e33-7d04dcf97744) | Sigma-Rules | Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) | Attack Pattern | 1 |