Update win_security_mitigations_defender_load_unsigned_dll.yml
This commit is contained in:
+1
-1
@@ -1,7 +1,7 @@
|
||||
title: Microsoft Defender Blocked from Loading Unsigned DLL
|
||||
id: 0b0ea3cc-99c8-4730-9c53-45deee2a4c86
|
||||
status: experimental
|
||||
description: Detects Code Integrity (CI) engine blocking Microsoft Defender's processes (MpCmdRun and NisSrv) from loading unsigned DLLs which may be an attempt to sideload arbitary DLL
|
||||
description: Detects Code Integrity (CI) engine blocking Microsoft Defender's processes (MpCmdRun and NisSrv) from loading unsigned DLLs which may be an attempt to sideload arbitrary DLL
|
||||
references:
|
||||
- https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool
|
||||
author: Bhabesh Raj
|
||||
|
||||
Reference in New Issue
Block a user