WINEKEY Registry Modification (b98968aa-dbc0-4a9c-ac35-108363cbf8d5)
Detects potential malicious modification of run keys by winekey or team9 backdoor
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
WINEKEY Registry Modification (b98968aa-dbc0-4a9c-ac35-108363cbf8d5) | Sigma-Rules | Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) | Attack Pattern | 1 |