Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184)

This commit is contained in:
frack113
2021-12-06 12:19:01 +01:00
committed by GitHub
parent 2d28767c04
commit 17899acbb0
4 changed files with 6 additions and 0 deletions

View File

@@ -17,6 +17,7 @@ Full_Path:
Code_Sample:
- Code:
Detection:
- Sigma: https://github.com/SigmaHQ/sigma/blob/0f33cbc85bf4b23b8d8308bfcc8b21a9e5431ee7/rules/windows/process_creation/win_pc_lolbas_extexport.yml
- IOC: Extexport.exe loads dll and is execute from other folder the original path
Resources:
- Link: http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/