mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Update sysmon_susp_procexplorer_driver_created_in_tmp_folder.yml
This commit is contained in:
parent
5790cc2ea7
commit
7d5e404b32
@ -15,13 +15,13 @@ logsource:
|
|||||||
category: file_event
|
category: file_event
|
||||||
detection:
|
detection:
|
||||||
selection_1:
|
selection_1:
|
||||||
TargetFilename: '*\AppData\Local\Temp\\*\PROCEXP152.sys'
|
TargetFilename|endswith: '\AppData\Local\Temp\\*\PROCEXP152.sys'
|
||||||
selection_2:
|
selection_2:
|
||||||
Image|contains:
|
Image|contains:
|
||||||
- '*\procexp64.exe'
|
- '\procexp64.exe'
|
||||||
- '*\procexp.exe'
|
- '\procexp.exe'
|
||||||
- '*\procmon64.exe'
|
- '\procmon64.exe'
|
||||||
- '*\procmon.exe'
|
- '\procmon.exe'
|
||||||
condition: selection_1 and not selection_2
|
condition: selection_1 and not selection_2
|
||||||
falsepositives:
|
falsepositives:
|
||||||
- Other legimate tools using this driver and filename (like Sysinternals). Note - Clever attackers may easily bypass this detection by just renaming the driver filename. Therefore just Medium-level and don't rely on it.
|
- Other legimate tools using this driver and filename (like Sysinternals). Note - Clever attackers may easily bypass this detection by just renaming the driver filename. Therefore just Medium-level and don't rely on it.
|
||||||
|
Loading…
Reference in New Issue
Block a user