13241300x800000000000000093321Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 10:09:52.408{0BACA6B2-24F0-655F-3B04-000000002903}4464C:\Windows\system32\reg.exeHKU\S-1-5-21-217062234-2484139415-3727922708-500\SOFTWARE\Microsoft\Terminal Server Client\AuthenticationLevelOverrideDWORD (0x00000000)ATTACKRANGE\Administrator