From 3c7b2bdc7f13e2ca15af4015b5a4ada93aa972d0 Mon Sep 17 00:00:00 2001 From: ciwen3 <55612276+ciwen3@users.noreply.github.com> Date: Tue, 3 Oct 2023 15:20:40 -0700 Subject: [PATCH] Update MpCmdRun.yml added path: C:\Program Files\Windows Defender\MpCmdRun.exe --- yml/OSBinaries/MpCmdRun.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/yml/OSBinaries/MpCmdRun.yml b/yml/OSBinaries/MpCmdRun.yml index 8ab314c..389e720 100644 --- a/yml/OSBinaries/MpCmdRun.yml +++ b/yml/OSBinaries/MpCmdRun.yml @@ -26,6 +26,7 @@ Commands: MitreID: T1564.004 OperatingSystem: Windows 10 Full_Path: + - Path: C:\Program Files\Windows Defender\MpCmdRun.exe - Path: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.4-0\MpCmdRun.exe - Path: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.7-0\MpCmdRun.exe - Path: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\MpCmdRun.exe