Jonhnathan
|
345c6627a8
|
Update win_mmc_spawn_shell.yml
|
2020-11-27 15:42:22 -03:00 |
|
Jonhnathan
|
5a0c7f6d11
|
Update win_mmc_spawn_shell.yml
|
2020-10-15 18:09:27 -03:00 |
|
Jonhnathan
|
e0ff1c09c9
|
Update win_mmc_spawn_shell.yml
|
2020-10-15 18:08:49 -03:00 |
|
Yugoslavskiy Daniil
|
11e0f794d9
|
review windows/process_creation part 4
|
2020-09-02 02:34:34 +02:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
Florian Roth
|
e79e99c4aa
|
fix: fixed missing date fields in remaining files
|
2020-01-30 16:07:37 +01:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Karneades
|
42e6c9149b
|
Remove unneeded event code
|
2019-08-05 19:13:39 +02:00 |
|
Karneades
|
5caa951b8f
|
Add new rule for detecting MMC spawning a shell
Add (analog to win_mshta_spawn_shell.yml) a dedicated rule for dedecting MMC spawning a shell. See https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_mshta_spawn_shell.yml. And it should cover the (removed) cmd part from the existing rule https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_mmc_source.yml.
|
2019-08-05 18:42:31 +02:00 |
|