Update image_load_defender_load_dll_from_nondefault_path.yml
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
title: Microsoft Defender Loading DLL from Nondefault Path
|
||||
id: 418dc89a-9808-4b87-b1d7-e5ae0cb6effc
|
||||
status: experimental
|
||||
description: Detects loading of Microsoft Defender's DLLs by its processes (MpCmdRun and NisSrv) from the non-default directory which may be an attempt to sideload arbitary DLL
|
||||
description: Detects loading of Microsoft Defender's DLLs by its processes (MpCmdRun and NisSrv) from the non-default directory which may be an attempt to sideload arbitrary DLL
|
||||
author: Bhabesh Raj
|
||||
date: 2022/08/02
|
||||
modified: 2022/08/17
|
||||
@@ -27,4 +27,4 @@ detection:
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
- Very unlikely
|
||||
level: high
|
||||
level: high
|
||||
|
||||
Reference in New Issue
Block a user