Added Sigma to Teams.exe (#329)

This commit is contained in:
securepeacock 2023-10-03 11:04:39 +00:00 committed by GitHub
parent a493c20989
commit fd9fae8321
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -13,6 +13,8 @@ Commands:
OperatingSystem: Windows 10, Windows 11
Full_Path:
- Path: c:\Users\username\AppData\Local\Microsoft\Teams\current\Teams.exe
Detection:
- Sigma: https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml
Resources:
Acknowledgement:
- Person: mr.d0x