mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2024-12-26 14:59:03 +01:00
Fix Code_Sample field
This commit is contained in:
parent
fc223eb3d8
commit
5012f95152
@ -15,7 +15,7 @@ Commands:
|
|||||||
Full_Path:
|
Full_Path:
|
||||||
- Path: C:\Windows\System32\eventvwr.exe
|
- Path: C:\Windows\System32\eventvwr.exe
|
||||||
- Path: C:\Windows\SysWOW64\eventvwr.exe
|
- Path: C:\Windows\SysWOW64\eventvwr.exe
|
||||||
Code Sample:
|
Code_Sample:
|
||||||
- Code: https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1
|
- Code: https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1
|
||||||
Detection:
|
Detection:
|
||||||
- IOC: eventvwr.exe launching child process other than mmc.exe
|
- IOC: eventvwr.exe launching child process other than mmc.exe
|
||||||
|
@ -14,7 +14,7 @@ Commands:
|
|||||||
OperatingSystem: Windows 10
|
OperatingSystem: Windows 10
|
||||||
Full_Path:
|
Full_Path:
|
||||||
- Path: C:\Windows\System32\wsreset.exe
|
- Path: C:\Windows\System32\wsreset.exe
|
||||||
Code Sample:
|
Code_Sample:
|
||||||
- Code:
|
- Code:
|
||||||
Detection:
|
Detection:
|
||||||
- IOC: wsreset.exe launching child process other than mmc.exe
|
- IOC: wsreset.exe launching child process other than mmc.exe
|
||||||
|
Loading…
Reference in New Issue
Block a user