Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392)

This commit is contained in:
p4yl0ad
2024-09-07 15:07:46 +01:00
committed by GitHub
parent 61bff01584
commit cfd827fe6d
7 changed files with 175 additions and 163 deletions

View File

@@ -14,6 +14,8 @@ Commands:
Full_Path:
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddinUtil.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddinUtil.exe
- Path: C:\Windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v3.5\AddInUtil.exe
Code_Sample:
- Code: https://gist.github.com/SILJAEUROPA/a850d476179d73df230a876944e9f3b1#file-addins-store
Detection:

View File

@@ -21,6 +21,10 @@ Commands:
Full_Path:
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\Csc.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Csc.exe
- Path: C:\Windows\Microsoft.NET\Framework\v3.5\csc.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v3.5\csc.exe
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe
Code_Sample:
- Code:
Detection:

View File

@@ -14,10 +14,10 @@ Commands:
Tags:
- Download: INetCache
Full_Path:
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.xxx\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.xxx\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.xxx\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.xxx\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe
Acknowledgement:
- Person: Avihay Eldad
Handle: '@AvihayEldad'

View File

@@ -25,8 +25,10 @@ Commands:
- Execute: DLL
- Input: Custom Format
Full_Path:
- Path: c:\Windows\Microsoft.NET\Framework\v*\regsvcs.exe
- Path: c:\Windows\Microsoft.NET\Framework64\v*\regsvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
Detection:
- Sigma: https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml
- Elastic: https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml

View File

@@ -23,8 +23,12 @@ Commands:
Tags:
- Execute: WSH
Full_Path:
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
- Path: C:\Windows\Microsoft.NET\Framework\v3.5\vbc.exe
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\vbc.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v3.5\vbc.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\vbc.exe
Code_Sample:
- Code:
Detection: