From 9adbbf36c167d4547ffbb3bef8c322980ecd19fb Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com> Date: Tue, 25 Oct 2022 23:48:54 +0200 Subject: [PATCH] Rename Rule --- ..._dll_load.yml => win_codeintegrity_attempted_dll_load.yml} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename rules/windows/builtin/code_integrity/{win_codeintegrity_failed_dll_load.yml => win_codeintegrity_attempted_dll_load.yml} (93%) diff --git a/rules/windows/builtin/code_integrity/win_codeintegrity_failed_dll_load.yml b/rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml similarity index 93% rename from rules/windows/builtin/code_integrity/win_codeintegrity_failed_dll_load.yml rename to rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml index 2d785c0f9..3f0a28d40 100644 --- a/rules/windows/builtin/code_integrity/win_codeintegrity_failed_dll_load.yml +++ b/rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml @@ -1,6 +1,6 @@ -title: Code Integrity Blocked DLL Load +title: Code Integrity Attempted DLL Load id: f8931561-97f5-4c46-907f-0a4a592e47a7 -description: Detects DLL load events that got blocked by Windows code integrity checks due to not meeting the Windows/Antimalware signing level requirements +description: Detects attempted DLL load events that didn't meet signing level requirements author: Florian Roth, Nasreddine Bencherchali (update) status: experimental references: