Added selection_5136 with new detection logic to support both detections
Modified ShareName to |endswith; as the previous string wouldn't convert properly with default pipeline configuration and sysvol should never appear in any other way unless there are weird configurations
ShareName
to |endswith; as the previous string wouldn't convert properly with default pipeline configuration andsysvol
should never appear in any other way unless there are weird configurationsSummary of the Pull Request
Changelog
update: Persistence and Execution at Scale via GPO Scheduled Task - Increase coverage by adding selection for EID 5136
Example Log Event
N/A
Fixed Issues
N/A
SigmaHQ Rule Creation Conventions