From 2e52cb7f868b9be0868ac35dcd63482d5dac3e64 Mon Sep 17 00:00:00 2001 From: omkargudhate22 <36105402+omkar72@users.noreply.github.com> Date: Wed, 14 Oct 2020 18:47:25 +0530 Subject: [PATCH] Update sysmon_susp_script_dotnet_clr_dll_load.yml --- .../image_load/sysmon_susp_script_dotnet_clr_dll_load.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml b/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml index 3a85034dd..701d372fa 100644 --- a/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml +++ b/rules/windows/image_load/sysmon_susp_script_dotnet_clr_dll_load.yml @@ -7,7 +7,7 @@ references: - https://thewover.github.io/Introducing-Donut/ - https://blog.menasec.net/2019/07/interesting-difr-traces-of-net-clr.html author: omkar72, oscd.community -date: 2020/10/10 +date: 2020/10/14 tags: - attack.execution - attack.privilege_escalation