Merge pull request #2653 from SigmaHQ/rule-devel

fix: FP noticed with Aurora
This commit is contained in:
Florian Roth
2022-02-07 13:15:47 +01:00
committed by GitHub
@@ -4,7 +4,7 @@ description: Raw disk access using illegitimate tools, possible defence evasion
author: Teymur Kheirkhabarov, oscd.community
status: test
date: 2019/10/22
modified: 2022/01/02
modified: 2022/02/06
references:
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
tags:
@@ -39,6 +39,7 @@ detection:
- '\MsMpEng.exe'
- '\SearchApp.exe'
- '\powershell.exe'
- '\GamingServices.exe'
filter_3:
ProcessId: 4
filter_fullpath: