Tim Shelton
|
f8ce6d87a8
|
adding filter for fp of iexplorer calling cpls: C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:276824072 WinX:0 WinY:0 IEFrame:0000000000000000
|
2022-01-27 16:31:37 +00:00 |
|
Florian Roth
|
4d5e87258d
|
Update win_run_executable_invalid_extension.yml
|
2022-01-14 11:47:46 +01:00 |
|
Tim Shelton
|
4f6d433c2d
|
Detects executable running with non executable extension, used for av bypass
|
2022-01-13 21:09:26 +00:00 |
|