diff --git a/nursery/reference-screen-saver-executable.yml b/nursery/reference-screen-saver-executable.yml deleted file mode 100644 index a916936f..00000000 --- a/nursery/reference-screen-saver-executable.yml +++ /dev/null @@ -1,19 +0,0 @@ -rule: - meta: - name: persist via screensaver registry key - namespace: persistence/screensaver - authors: - - michael.hunhoff@mandiant.com - description: SCRNSAVE.EXE registry value specifies the name of the screen saver executable file - scopes: - static: function - dynamic: call - att&ck: - - Persistence::Event Triggered Execution::Screensaver [T1546.002] - features: - - and: - - match: set registry value - - string: /Control Panel\\Desktop/i - - string: /^SCRNSAVE.EXE$/i - - optional: - - string: "ScreenSaveTimeOut"