Fixing some paths / adding some paths, this will improve upstream hunting tool efficacy if proper paths are referenced in the yml (#392)

This commit is contained in:
p4yl0ad
2024-09-07 15:07:46 +01:00
committed by GitHub
parent 61bff01584
commit cfd827fe6d
7 changed files with 175 additions and 163 deletions

View File

@@ -25,8 +25,10 @@ Commands:
- Execute: DLL
- Input: Custom Format
Full_Path:
- Path: c:\Windows\Microsoft.NET\Framework\v*\regsvcs.exe
- Path: c:\Windows\Microsoft.NET\Framework64\v*\regsvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
Detection:
- Sigma: https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml
- Elastic: https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml