mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-07-27 04:32:24 +02:00
@@ -44,8 +44,6 @@ Commands:
|
||||
Full_Path:
|
||||
- Path: C:\Windows\System32\dsdbutil.exe
|
||||
- Path: C:\Windows\SysWOW64\dsdbutil.exe
|
||||
Code_Sample:
|
||||
- Code:
|
||||
Detection:
|
||||
- IOC: Event ID 4688
|
||||
- IOC: dsdbutil.exe process creation
|
||||
|
Reference in New Issue
Block a user