diff --git a/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml b/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml index 3a85034dd..701d372fa 100644 --- a/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml +++ b/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml @@ -7,7 +7,7 @@ references: - https://thewover.github.io/Introducing-Donut/ - https://blog.menasec.net/2019/07/interesting-difr-traces-of-net-clr.html author: omkar72, oscd.community -date: 2020/10/10 +date: 2020/10/14 tags: - attack.execution - attack.privilege_escalation