Hide Navigation Hide TOC HackTool - SysmonEnte Execution (d29ada0f-af45-4f27-8f32-f7b77c3dbc4e) Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon Cluster A Galaxy A Cluster B Galaxy B Level HackTool - SysmonEnte Execution (d29ada0f-af45-4f27-8f32-f7b77c3dbc4e) Sigma-Rules Disable or Modify Windows Event Log - T1685.001 (1411e6b8-80a6-4465-9909-54eaa9c67ce0) Attack Pattern 1 Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Disable or Modify Windows Event Log - T1685.001 (1411e6b8-80a6-4465-9909-54eaa9c67ce0) Attack Pattern 2