SigmaHQ / sigma

Main Sigma Rule Repository
Other
8.19k stars 2.17k forks source link

Add logic to win_security_gpo_scheduledtasks.yml #5000

Closed joshnck closed 3 weeks ago

joshnck commented 3 weeks ago

Summary of the Pull Request

Changelog

update: Persistence and Execution at Scale via GPO Scheduled Task - Increase coverage by adding selection for EID 5136

Example Log Event

N/A

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions