This commit is contained in:
alexpetrov12
2019-10-23 02:47:04 +03:00
parent ebe4fe0377
commit f4ea01217e
3 changed files with 22 additions and 22 deletions
@@ -13,8 +13,8 @@ logsource:
product: windows
detection:
selection:
Image:'*\rundll32.exe'
CommandLine:'*comsvcs.dll*minidump*'
Image: '*\rundll32.exe'
CommandLine: '*comsvcs.dll*minidump*'
condition: selection
falsepositives:
- unknown
@@ -15,24 +15,24 @@ logsource:
detection:
selection:
Description:
- "active directory editor"
- "sysinternals process dump utility"
- "msbuild.exe"
- ".net core host"
- "windows command processor"
- "windows powershell"
- "execute processes remotely"
- ".net framework installation utility"
- "microsoft ® console based script host"
- "microsoft ® windows based script host"
- "microsoft (r) html application host"
- "microsoft(c) register server"
- "wmi commandline utility"
- "certutil.exe"
- "windows host process (rundll32)"
- "microsoft connection manager profile Installer"
- "windows ® installer"
- "7-zip console"
-"active directory editor"
-"sysinternals process dump utility"
-"msbuild.exe"
-".net core host"
-"windows command processor"
-"windows powershell"
-"execute processes remotely"
-".net framework installation utility"
-"microsoft ® console based script host"
-"microsoft ® windows based script host"
-"microsoft (r) html application host"
-"microsoft(c) register server"
-"wmi commandline utility"
-"certutil.exe"
-"windows host process (rundll32)"
-"microsoft connection manager profile Installer"
-"windows ® installer"
-"7-zip console"
filter:
Image:
-'*\adexplorer.exe'
@@ -15,8 +15,8 @@ logsource:
detection:
selection:
EventID: 4688
ProcessName:'*\fltMC.exe'
CommandLine:'*unload*Sys*'
ProcessName: '*\fltMC.exe'
CommandLine: '*unload*Sys*'
selection1:
EventID: 4673
PrivilegeList: '*\SeLoadDriverPrivilege'