UBA : Malware Activity - Registry Modified In Bulk

The QRadar® User Behavior Analytics (UBA) app supports use cases based on rules for certain behavioral anomalies.

UBA : Malware Activity - Registry Modified In Bulk

Enabled by default

False

Default senseValue

15

Description

Detects processes that modify multiple registry values in bulk within a shorter interval.

Support rule

BB:UBA : Common Event Filters

Log source types

Microsoft Windows Security Event Logs (EventID: 4657)