Update image_load_side_load_dbghelp_dll.yml

This commit is contained in:
Nasreddine Bencherchali
2022-10-25 12:33:49 +02:00
parent 205cb7bc2e
commit e14dedb3e3
@@ -19,13 +19,13 @@ detection:
selection:
ImageLoaded|endswith: '\dbghelp.dll'
filter_generic:
ImageLoaded:
- ImageLoaded:
- 'C:\Program Files (x86)\Microsoft Analysis Services\AS OLEDB\110\dbghelp.dll'
- 'C:\Program Files\Microsoft Analysis Services\AS OLEDB\110\dbghelp.dll'
- 'C:\Program Files\Common Files\microsoft shared\DW\DBGHELP.DLL'
- 'C:\Program Files\Dell\DTP\InstrumentationSubAgent\dbghelp.dll'
- 'C:\Program Files\DTrace\dbghelp.dll'
ImageLoaded|startswith:
- ImageLoaded|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C:\Windows\WinSxS\'
@@ -38,7 +38,7 @@ detection:
- 'C:\Program Files\Microsoft Office\Office'
- 'C:\Program Files\Microsoft Office\Root\Office'
- 'C:\Program Files\WindowsApps\Microsoft.WinDbg_'
ImageLoaded|endswith:
- ImageLoaded|endswith:
- '\Epic Games\Launcher\Engine\Binaries\ThirdParty\DbgHelp\dbghelp.dll'
- '\Epic Games\MagicLegends\x86\dbghelp.dll'
- '\Anaconda3\Lib\site-packages\vtrace\platforms\windll\amd64\dbghelp.dll'