Open tidalwaave opened 11 months ago
C:\Users\
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
index=* source="WinEventLog:Sysmon"
EventCode=11
(TargetFilename="C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup"
OR TargetFilename="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup")
File created in Startup Folder Potential persistence setup
LOW severity
Medium