From 4030c53cd11651dc74be50210db11f60c7ceea26 Mon Sep 17 00:00:00 2001 From: root Date: Sun, 12 Jan 2025 02:57:40 +0300 Subject: [PATCH] printui.exe lolbas request --- yml/OSBinaries/printui.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/yml/OSBinaries/printui.yml b/yml/OSBinaries/printui.yml index 3c0d62a..2fc0974 100644 --- a/yml/OSBinaries/printui.yml +++ b/yml/OSBinaries/printui.yml @@ -16,10 +16,11 @@ Commands: Full_Path: - Path: C:\Windows\System32\printui.exe Detection: - - Sigma: https:https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_side_load_from_non_system_location.yml + - Sigma: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_side_load_from_non_system_location.yml - IOC: Load malicious DLL image Resources: - - Link: https:https://www.linkedin.com/pulse/uncovered-lolbas-yasin-g%C3%B6khan-ta%C5%9Fkin-gnpwf/?trackingId=WvE5YmopTtyh%2FuvEPcpyZQ%3D%3D + - Link: https://www.linkedin.com/pulse/uncovered-lolbas-yasin-g%C3%B6khan-ta%C5%9Fkin-gnpwf/?trackingId=WvE5YmopTtyh%2FuvEPcpyZQ%3D%3D + - Link: https://x.com/TaskinYasn/status/1876672639558947213 Acknowledgement: - Person: Yasin Gökhan TAŞKIN Handle: '@TaskinYasn'