diff --git a/rules/windows/image_load/image_load_side_load_wermgr_comctl32.yml b/rules/windows/image_load/image_load_side_load_wermgr_comctl32.yml index d7692fc59..39a6d77ca 100644 --- a/rules/windows/image_load/image_load_side_load_wermgr_comctl32.yml +++ b/rules/windows/image_load/image_load_side_load_wermgr_comctl32.yml @@ -1,7 +1,7 @@ title: Potential DLL Sideloading Via comctl32.dll id: 6360757a-d460-456c-8b13-74cf0e60cceb status: experimental -description: Detects potential DLL sideloading using comctl32.dll via "wermgr.exe" to obtain system privileges +description: Detects potential DLL sideloading using comctl32.dll to obtain system privileges references: - https://github.com/binderlabs/DirCreate2System - https://github.com/sailay1996/awesome_windows_logical_bugs/blob/60cbb23a801f4c3195deac1cc46df27c225c3d07/dir_create2system.txt