From 248dcbe7358e366830236fca0890f15fd40a87e7 Mon Sep 17 00:00:00 2001 From: Austin Songer Date: Fri, 26 Nov 2021 14:34:32 -0600 Subject: [PATCH] Update process_creation_win_lolbas_dump64.yml --- .../process_creation/process_creation_win_lolbas_dump64.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/process_creation/process_creation_win_lolbas_dump64.yml b/rules/windows/process_creation/process_creation_win_lolbas_dump64.yml index cd8247c86..db18ef626 100644 --- a/rules/windows/process_creation/process_creation_win_lolbas_dump64.yml +++ b/rules/windows/process_creation/process_creation_win_lolbas_dump64.yml @@ -3,7 +3,7 @@ id: 129966c9-de17-4334-a123-8b58172e664d description: Detects when a user bypasses Defender by renaming a tool to dump64.exe and placing it in a Visual Studio folder status: experimental author: Austin Songer @austinsonger, Florian Roth -date: 2021/11//26 +date: 2021/11/26 references: - https://twitter.com/mrd0x/status/1460597833917251595 logsource: