Detection rules › By eventMicrosoft-Windows-Kernel-General event 161 detection rule reference this event. View event page.Sigma (1)Critical Hive In Suspicious Location Access Bits Cleared severity high T1003.002