title: test id: ff151c33-45fa-475d-af4f-c2f93571f4fe description: | list test status: experimental date: 2021/12/4 author: test logsource: product: windows service: security detection: selection: EventID: - 4100 - 9000 - 8000 - "aaaa" ObjectType: 'Key' condition: selection falsepositives: - Unknown level: medium