From 1a51d53e9f8e5cb6cd2b9297e80366e2abcbce0b Mon Sep 17 00:00:00 2001 From: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com> Date: Tue, 28 Apr 2026 02:15:50 +0545 Subject: [PATCH] Merge PR #5829 from @swachchhanda000 - Add `PUA - Memory Dump Mount Via MemProcFS` new: PUA - Memory Dump Mount Via MemProcFS --------- Co-authored-by: Nasreddine Bencherchali --- .../8a1b2c3d-4e5f-6789-abcd-ef1234567890.evtx | Bin 0 -> 69632 bytes .../8a1b2c3d-4e5f-6789-abcd-ef1234567890.json | 66 ++++++++++++++++++ .../proc_creation_win_pua_memprocfs/info.yml | 13 ++++ .../proc_creation_win_pua_memprocfs.yml | 35 ++++++++++ 4 files changed, 114 insertions(+) create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_pua_memprocfs/8a1b2c3d-4e5f-6789-abcd-ef1234567890.evtx create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_pua_memprocfs/8a1b2c3d-4e5f-6789-abcd-ef1234567890.json create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_pua_memprocfs/info.yml create mode 100644 rules/windows/process_creation/proc_creation_win_pua_memprocfs.yml diff --git a/regression_data/rules/windows/process_creation/proc_creation_win_pua_memprocfs/8a1b2c3d-4e5f-6789-abcd-ef1234567890.evtx b/regression_data/rules/windows/process_creation/proc_creation_win_pua_memprocfs/8a1b2c3d-4e5f-6789-abcd-ef1234567890.evtx new file mode 100644 index 0000000000000000000000000000000000000000..3a407d1d61dc8d8f3d967bdbfcca5cabb966e088 GIT binary patch literal 69632 zcmeI0TWnlc6^7S2o*9qFo*BD|xr8PpX}KiSj^n$V24s&tB-Cy~F9akDNKs#7zPu!b62B(IUhf5~`4pkP2@Fp-5bWB2Zt-3sON9pbDA)-)C=+?buFA zUU>M==*-!dwbx$zTWha6 z&zahn)9c0dX3TO~vwxuV_0;+vvu?B>$KMcd_j>gfW1hvFy!Lua{^{j^|{@`D)J$&#lzrVinQri!{j+IbqxXr$ZA{WT(<(9OK z*;6)WRa-{=OSm&n_|Bgd({|YwZ2_G%bflv`I|s34yI}X*5qxSkgO)kSOrzY1X9X=! z+7fC@HV?^8)R)kH#4e$)if6ZV;nRy!mkr{3Zf*M7hFTo0u3m?)g5Q=N&DbM$1)7)L zj0o`I)zweIuHex(u4e7DoBb)wH4CXH(c6!^9D?z|Z>8)Z7`up0vqHh5%qM+39BNP5 zNA02;iLRm*8-^Qf0%D)_5^qj7u7h>bM$z{H+!=-()g1a`&OQzm(?C|i@+-~+qAR2< z6BimRlZu+{AR0oXzpJUyKHhP(DI)LN}*C-7{}9dKI0X=p1UFa8F(@++8T*HqG%#%AD^=F}6g zd1JEburp|@!plowP_qsnu8XKwZEEnsnZv*MbLr>fnKvt6d+QHxcl;5z?}&o?BZ*38 ziX?e|?&R`dI5Jpno;fxZeeBs^{pYbC?!EzsQ3^i%Es8vKd5wOa0Tz8N{+l<#ti|~T%ToS;m#6o=^=X6@51zBIKh7hJ zwzZ`U+Fa$vL>uSRJB%5HJdZa<_JuWn#rez*e3HXw7EGB~;(X%{vdmK4eB7y5Ae&8O z2mCt8$FH*$aYHN4;;uq|!NPjNNfzguc34R=6G<_$$DI}u!-gWUEoUsbJXuT6jt8j zN4D2TW{{BhD#Vwf8fA#Iz=)JF&BRFMoj$EI<-dS3?7=aS z-0a_j`!l$o!+kGq9sxWqk|QFr!^o0sW4#~!&wIHJ_uAQwwhp{@9(CV?wjZUVc$Mw3 zK74oE5awrZukE|%JJHkMo~m4PsWxxl+haH`@3+ad*sh^`8PPk7m^z2@D9V=*H4Au7 zqm}&=h=RqnOjyQgGUeV1nTu*DCp&V=9`|v|SYuBIG%<3gFhf7A>44Vcor*8NTj}k@ zIKFB0VFgDqrqivZ8*A#>!it;i>exam=)74v^y~-04y=`Lr94aLP@i#>xObS{CjCl| zf@@d{^CSB@5&hHX|Nr5--J8#PPct%Jc;(ZT-8Uk{tXX)nb^;X6A{r(T4SjYTp6kT{ z-GzJ9Mv%2fQ6Iu{3?8Dy5bhouz|WvwP+%`(uiv$mAax%i<^$f>}rKybpPC0`W|nXxVW$XFsGl8!hTbPcKIG;kygYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmY zKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmY zKmYKmYKmYKmYKmYKm