Detection rules › Sigma
Sysmon Configuration Change
Detects a Sysmon configuration change, which could be the result of a legitimate reconfiguration or someone trying manipulate the configuration
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Sysmon | 16 | ServiceConfigurationChange |