From 73c953d633b1433ba3e19f3512543098acdb7037 Mon Sep 17 00:00:00 2001 From: frack113 <62423083+frack113@users.noreply.github.com> Date: Sat, 21 Aug 2021 16:18:16 +0200 Subject: [PATCH] Fix title --- rules/windows/file_event/sysmon_detect_powerup_dllhijacking.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/file_event/sysmon_detect_powerup_dllhijacking.yml b/rules/windows/file_event/sysmon_detect_powerup_dllhijacking.yml index 326fb189d..8006f0023 100644 --- a/rules/windows/file_event/sysmon_detect_powerup_dllhijacking.yml +++ b/rules/windows/file_event/sysmon_detect_powerup_dllhijacking.yml @@ -1,4 +1,4 @@ -title: Powerup Write Hijack DLL detection +title: Powerup Write Hijack DLL id: 602a1f13-c640-4d73-b053-be9a2fa58b96 status: experimental description: Powerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default). Reference - https://powersploit.readthedocs.io/en/latest/Privesc/Write-HijackDll/