mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
fix
This commit is contained in:
parent
e38540a37f
commit
043e3f7ca6
@ -1,23 +0,0 @@
|
||||
title: Sysmon driver unload
|
||||
status: experimental
|
||||
author: Kirill Kiryanov, oscd.community
|
||||
description: Detect possible shutdown Sysmon
|
||||
references:
|
||||
- https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
|
||||
fields:
|
||||
- CommandLine
|
||||
- Details
|
||||
falsepositives: Unknown
|
||||
level: medium
|
||||
logsource:
|
||||
product: windows
|
||||
service: security
|
||||
detection:
|
||||
selection:
|
||||
EventID: 4688
|
||||
ProcessName: '*\fltMC.exe'
|
||||
CommandLine: '*unload*Sys*'
|
||||
selection1:
|
||||
EventID: 4673
|
||||
PrivilegeList: '*\SeLoadDriverPrivilege'
|
||||
condition: selection and selection1
|
Loading…
Reference in New Issue
Block a user