mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
regsvr32 anomaly rule update
https://twitter.com/BlackMatter23/status/1417545425297580045
This commit is contained in:
parent
66aaa2210c
commit
ddb4744613
@ -4,6 +4,7 @@ status: experimental
|
||||
description: Detects a regsvr.exe execution that doesn't contain a DLL in the command line
|
||||
author: Florian Roth
|
||||
date: 2019/07/17
|
||||
modified: 2021/07/20
|
||||
references:
|
||||
- https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/
|
||||
tags:
|
||||
@ -21,6 +22,8 @@ detection:
|
||||
- '.ocx'
|
||||
- '.cpl'
|
||||
- '.ax'
|
||||
- '.bav'
|
||||
- '.ppl'
|
||||
condition: selection and not filter
|
||||
fields:
|
||||
- CommandLine
|
||||
|
Loading…
Reference in New Issue
Block a user