From bfa5e4ecf5fbb176affea3d7bf1cc405d3e37276 Mon Sep 17 00:00:00 2001 From: frack113 <62423083+frack113@users.noreply.github.com> Date: Fri, 16 Dec 2022 08:28:45 +0100 Subject: [PATCH] Update rules/windows/process_creation/proc_creation_win_rundll32_parent_explorer.yml Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com> --- .../proc_creation_win_rundll32_parent_explorer.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/rules/windows/process_creation/proc_creation_win_rundll32_parent_explorer.yml b/rules/windows/process_creation/proc_creation_win_rundll32_parent_explorer.yml index 3730ef49d..b9c8c39ab 100644 --- a/rules/windows/process_creation/proc_creation_win_rundll32_parent_explorer.yml +++ b/rules/windows/process_creation/proc_creation_win_rundll32_parent_explorer.yml @@ -6,7 +6,8 @@ references: - https://redcanary.com/blog/raspberry-robin/ - https://thedfirreport.com/2022/09/26/bumblebee-round-two/ author: CD_ROM_ -date: 2022/12/15 +date: 2022/05/21 +modified: 2022/12/15 tags: - attack.defense_evasion logsource: