Rule: Follina and DogWalk exploit msdt.exe loading sdiageng.dll

This commit is contained in:
eiger
2022-06-17 09:41:08 +08:00
parent 7444869de3
commit e4ab54d60f
@@ -4,8 +4,6 @@ status: experimental
description: Detects both of CVE-2022-30190 and DogWalk vulnerability exploiting "msdt.exe" binary to load "sdiageng.dll" binary.
author: Greg (rule)
references:
- https://twitter.com/j00sean/status/1534115332830507008
- https://twitter.com/nas_bench/status/1531944240271568896?t=z0hjfsgRgNb9c4NCLk-bHg&s=19
- https://www.securonix.com/blog/detecting-microsoft-msdt-dogwalk/
date: 2022/06/09
modified: 2022/06/17