Sysmon Configuration Error (815cd91b-7dbc-4247-841a-d7dd1392b0a8)
Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) | Attack Pattern | Sysmon Configuration Error (815cd91b-7dbc-4247-841a-d7dd1392b0a8) | Sigma-Rules | 1 |