Some fixes for rules

This commit is contained in:
uchakin 2020-10-14 19:06:59 +03:00
parent a73dbd0a5d
commit a7e5b0ac40
3 changed files with 6 additions and 4 deletions

View File

@ -17,10 +17,13 @@ logsource:
product: windows
detection:
selection:
Image:
Image|endswith:
- '\dism.exe'
ImageLoaded:
ImageLoaded|endswith:
- '\dismcore.dll'
filter:
ImageLoaded:
- 'C:\Windows\System32\Dism\dismcore.dll'
condition: selection
falsepositives:
- Pentests

View File

@ -16,7 +16,7 @@ logsource:
product: windows
detection:
selection:
CallTrace: '*editionupgrademanagerobj.dll*'
CallTrace|contains: '*editionupgrademanagerobj.dll*'
condition: selection
fields:
- ComputerName

View File

@ -5,7 +5,6 @@ description: Unfixed method for UAC bypass from windows 10. WSReset.exe file ass
references:
- https://www.bleepingcomputer.com/news/security/trickbot-uses-a-new-windows-10-uac-bypass-to-launch-quietly
- https://lolbas-project.github.io/lolbas/Binaries/Wsreset
tags:
- attack.defense_evasion
- attack.privilege_escalation