diff --git a/yml/OSBinaries/Conhost.yml b/yml/OSBinaries/Conhost.yml index 8fed6e3..7ce1d4e 100644 --- a/yml/OSBinaries/Conhost.yml +++ b/yml/OSBinaries/Conhost.yml @@ -16,8 +16,11 @@ Full_Path: Detection: - IOC: conhost.exe spawning unexpected processes Resources: + - Link: https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/ - Link: https://twitter.com/Wietze/status/1511397781159751680 Acknowledgement: + - Person: Adam + Handle: '@hexacorn' - Person: Wietze Handle: '@wietze' ---