This commit is contained in:
Nasreddine Bencherchali
2022-11-03 09:39:48 +01:00
parent 1d37ec5f74
commit 5ee9428e59
6 changed files with 46 additions and 19 deletions
@@ -28,6 +28,8 @@ detection:
# In some cases powershell was invoked with inverted slashes
- '= C:/Windows/System32/WindowsPowerShell/v1.0/powershell'
- '= C:/Windows/SysWOW64/WindowsPowerShell/v1.0/powershell'
# When MSDT is launched
- '= C:\WINDOWS\System32\sdiagnhost.exe -Embedding '
filter_citrix:
ContextInfo|contains: 'ConfigSyncRun.exe'
filter_adace: # Active Directory Administrative Center Enhancements