diff --git a/yml/OtherMSBinaries/Wsl.yml b/yml/OtherMSBinaries/Wsl.yml index 490c12b..cdb1be4 100644 --- a/yml/OtherMSBinaries/Wsl.yml +++ b/yml/OtherMSBinaries/Wsl.yml @@ -28,4 +28,9 @@ Detection: - IOC: Child process from wsl.exe Resources: - Link: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules + Acknowledgement: + - Person: Alex Ionescu + Handle: '@aionescu' + - Person: Matt + Handle: '@NotoriousRebel1' ---