13241300x800000000000000085709Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 08:42:20.825{0BACA6B2-106C-655F-E301-000000002903}4448C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableRemoteDesktopAntiAliasDWORD (0x00000001)ATTACKRANGE\Administrator
13241300x800000000000000085704Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 08:42:20.746{0BACA6B2-106C-655F-E201-000000002903}4968C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services(Empty)ATTACKRANGE\Administrator