From e08b10f437dbdd35d5878f673971a340af04f550 Mon Sep 17 00:00:00 2001 From: frack113 <62423083+frack113@users.noreply.github.com> Date: Sat, 17 Jun 2023 21:29:07 +0200 Subject: [PATCH] Fix sigmaHQ ref (#300) Signed-off-by: frack113 <62423083+frack113@users.noreply.github.com> --- yml/OtherMSBinaries/vsls-agent.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/yml/OtherMSBinaries/vsls-agent.yml b/yml/OtherMSBinaries/vsls-agent.yml index cb4ea0f..b5f4b7f 100644 --- a/yml/OtherMSBinaries/vsls-agent.yml +++ b/yml/OtherMSBinaries/vsls-agent.yml @@ -14,7 +14,7 @@ Commands: Full_Path: - Path: c:\Program Files (x86)\Microsoft Visual Studio\2019\Professional\Common7\IDE\Extensions\Microsoft\LiveShare\Agent\vsls-agent.exe Detection: - - Sigma: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_vslsagent_agentextensionpath_load.yml + - Sigma: https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_vslsagent_agentextensionpath_load.yml Resources: - Link: https://twitter.com/bohops/status/1583916360404729857 Acknowledgement: