12241200x80000000000000007762Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-DeleteKey2025-07-17 09:23:35.241{E4B49A97-C117-6878-1502-00000000EE03}5848C:\Windows\system32\reg.exeHKU\S-1-5-21-1112602589-2034875377-1972765770-500\SOFTWARE\Microsoft\Terminal Server Client\ServersATTACKRANGE\Administrator 12241200x80000000000000007761Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-DeleteKey2025-07-17 09:23:35.241{E4B49A97-C117-6878-1502-00000000EE03}5848C:\Windows\system32\reg.exeHKU\S-1-5-21-1112602589-2034875377-1972765770-500\SOFTWARE\Microsoft\Terminal Server Client\Servers\10.0.1.15ATTACKRANGE\Administrator 12241200x80000000000000007759Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-DeleteValue2025-07-17 09:23:35.226{E4B49A97-C117-6878-1402-00000000EE03}4808C:\Windows\system32\reg.exeHKU\S-1-5-21-1112602589-2034875377-1972765770-500\SOFTWARE\Microsoft\Terminal Server Client\Default\MRU0ATTACKRANGE\Administrator