mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2024-12-28 15:58:24 +01:00
Added Sigma to Teams.exe (#329)
This commit is contained in:
parent
a493c20989
commit
fd9fae8321
@ -13,6 +13,8 @@ Commands:
|
|||||||
OperatingSystem: Windows 10, Windows 11
|
OperatingSystem: Windows 10, Windows 11
|
||||||
Full_Path:
|
Full_Path:
|
||||||
- Path: c:\Users\username\AppData\Local\Microsoft\Teams\current\Teams.exe
|
- Path: c:\Users\username\AppData\Local\Microsoft\Teams\current\Teams.exe
|
||||||
|
Detection:
|
||||||
|
- Sigma: https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml
|
||||||
Resources:
|
Resources:
|
||||||
Acknowledgement:
|
Acknowledgement:
|
||||||
- Person: mr.d0x
|
- Person: mr.d0x
|
||||||
|
Loading…
Reference in New Issue
Block a user