13241300x800000000000000093564Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 10:12:07.455{0BACA6B2-2575-655F-5204-000000002903}3076C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000001)ATTACKRANGE\Administrator 13241300x800000000000000093556Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 10:12:02.514{0BACA6B2-2570-655F-5104-000000002903}5084C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000000)ATTACKRANGE\Administrator 13241300x800000000000000093501Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 10:11:57.026{0BACA6B2-2566-655F-4604-000000002903}4752C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000001)ATTACKRANGE\Administrator 13241300x800000000000000093113Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1484SetValue2023-11-23 10:07:58.877{0BACA6B2-247E-655F-2C04-000000002903}3772C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000001)ATTACKRANGE\Administrator 13241300x800000000000000039551Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localT1484SetValue2023-11-23 09:57:13.437{F3BFD260-21F9-655F-B203-000000002803}4728C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000001)ATTACKRANGE\Administrator 13241300x800000000000000039519Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localT1484SetValue2023-11-23 09:54:00.663{F3BFD260-20D3-655F-8E03-000000002803}4740C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000001)ATTACKRANGE\Administrator 13241300x800000000000000039499Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localT1484SetValue2023-11-23 09:51:47.222{F3BFD260-20B3-655F-8503-000000002803}4112C:\Windows\system32\reg.exeHKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\DisableSecuritySettingsDWORD (0x00000001)ATTACKRANGE\Administrator