Remote Registry Lateral Movement (35c55673-84ca-4e99-8d09-e334f3c29539)
Detects remote RPC calls to modify the registry and possible execute code
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Remote Registry Lateral Movement (35c55673-84ca-4e99-8d09-e334f3c29539) | Sigma-Rules | Modify Registry - T1112 (57340c81-c025-4189-8fa0-fc7ede51bae4) | Attack Pattern | 1 |