refactor: minor changes to procdump rule
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
title: Procdump Evasion
|
||||
id: 79b06761-465f-4f88-9ef2-150e24d3d737
|
||||
description: Detects uses of the SysInternals Procdump utility in which procdump or its output get renamed
|
||||
description: Detects uses of the SysInternals Procdump utility in which procdump or its output get renamed or a dump file is moved ot copied to a different name
|
||||
status: experimental
|
||||
references:
|
||||
- https://twitter.com/mrd0x/status/1480785527901204481
|
||||
@@ -29,6 +29,7 @@ detection:
|
||||
selection3:
|
||||
CommandLine|contains:
|
||||
- 'copy lsass.exe_' # procdump default pattern e.g. lsass.exe_220111_085234.dmp
|
||||
- 'move lsass.exe_' # procdump default pattern e.g. lsass.exe_220111_085234.dmp
|
||||
condition: 1 of selection*
|
||||
falsepositives:
|
||||
- Cases in which procdump just gets copied to a different directory without any renaming
|
||||
|
||||
Reference in New Issue
Block a user