Update image_load_defender_load_dll_from_nondefault_path.yml

This commit is contained in:
Wagga
2022-08-29 07:28:07 +02:00
committed by GitHub
parent d8852f6fa6
commit dc9f4fbb49
@@ -1,7 +1,7 @@
title: Microsoft Defender Loading DLL from Nondefault Path
id: 418dc89a-9808-4b87-b1d7-e5ae0cb6effc
status: experimental
description: Detects loading of Microsoft Defender's DLLs by its processes (MpCmdRun and NisSrv) from the non-default directory which may be an attempt to sideload arbitary DLL
description: Detects loading of Microsoft Defender's DLLs by its processes (MpCmdRun and NisSrv) from the non-default directory which may be an attempt to sideload arbitrary DLL
author: Bhabesh Raj
date: 2022/08/02
modified: 2022/08/17
@@ -27,4 +27,4 @@ detection:
condition: selection and not filter
falsepositives:
- Very unlikely
level: high
level: high