sigma/Add sysmon_renamed_binary

This commit is contained in:
mgreen27
2019-06-15 20:20:52 +10:00
parent 1d26708887
commit 07e2ee474c
@@ -1,6 +1,6 @@
title: Renamed Binary
status: experimental
description: Detects the execution of a renamed binary often used by attackers or malware leveraging new
description: Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
author: Matthew Green - @mgreen27
date: 2019/06/15
references: