12241200x800000000000000013262Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1060,RunPolicyDeleteValue2024-06-21 09:25:49.545{848A6B75-314B-6675-1500-000000000B03}1128C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{0D807408-8157-49B9-ACFC-0B5C15B1119E}NT AUTHORITY\LOCAL SERVICE
13241300x800000000000000013249Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.localT1060,RunPolicySetValue2024-06-21 09:23:13.441{848A6B75-314B-6675-1500-000000000B03}1128C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{0D807408-8157-49B9-ACFC-0B5C15B1119E}v2.26|Action=Allow|Active=TRUE|Dir=In|App=C:\MyApp\MyApp1.exe|Name=Mytestfirewal1|NT AUTHORITY\LOCAL SERVICE