SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.73k stars 1.69k forks source link

MiniNT registry key check #130

Open ThisIsNotTheUserYouAreLookingFor opened 4 years ago

ThisIsNotTheUserYouAreLookingFor commented 4 years ago

added a MiniNT regkey check, as it can be used to disable security event logging

SwiftOnSecurity commented 3 years ago

Hello could you tell me more about this the tweet is missing

aronmorgulis commented 3 years ago

Hello could you tell me more about this the tweet is missing

https://www.quppa.net/blog/2016/04/14/beware-of-the-minint-registry-key/