mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2024-12-27 07:18:05 +01:00
Added Sigma to Teams.exe (#329)
This commit is contained in:
parent
a493c20989
commit
fd9fae8321
@ -13,6 +13,8 @@ Commands:
|
||||
OperatingSystem: Windows 10, Windows 11
|
||||
Full_Path:
|
||||
- Path: c:\Users\username\AppData\Local\Microsoft\Teams\current\Teams.exe
|
||||
Detection:
|
||||
- Sigma: https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml
|
||||
Resources:
|
||||
Acknowledgement:
|
||||
- Person: mr.d0x
|
||||
|
Loading…
Reference in New Issue
Block a user