From 0f6b03e68ad525a396c35b14b04a936301610a30 Mon Sep 17 00:00:00 2001 From: Tonmoy Jitu <52621226+tonmoy0010@users.noreply.github.com> Date: Thu, 19 Dec 2024 23:34:21 +1100 Subject: [PATCH] removed unwanted line --- yml/OSBinaries/Wevtutil.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/yml/OSBinaries/Wevtutil.yml b/yml/OSBinaries/Wevtutil.yml index 83a82372..dd78d854 100644 --- a/yml/OSBinaries/Wevtutil.yml +++ b/yml/OSBinaries/Wevtutil.yml @@ -28,8 +28,6 @@ Commands: Full_Path: - Path: C:\Windows\System32\wevtutil.exe - Path: C:\Windows\SysWOW64\wevtutil.exe -Code_Sample: - - Code: https://example.com/sample-code Detection: - IOC: Use of wevtutil cl in command-line logs. - IOC: Multiple wevtutil qe commands targeting specific Event IDs.