412edd1e1a
new: DLL Names Used By SVR For GraphicalProton Backdoor new: Enable LM Hash Storage new: Enable LM Hash Storage - ProcCreation new: Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor new: Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor - Task Scheduler update: Compress-Archive Cmdlet Execution - Reudced Level to low and moved to Threat Hunting folder. update: Disabled Volume Snapshots - Update logic by removing the reg string to also account for potential renamed executions update: Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet - Update logic to be more specific update: Potential Recon Activity Via Nltest.EXE - Add dnsgetdc coverage and enhance logic by removing / update: Potential System DLL Sideloading From Non System Locations - Enhance logic by removing hardcoded C: value to account for other potential system locations update: RestrictedAdminMode Registry Value Tampering - ProcCreation - Update logic the logic to not care about the data. As this registry value has use cases either be it "0" or "1" update: RestrictedAdminMode Registry Value Tampering - Update logic the logic to not care about the data. As this registry value has use cases either be it "0" or "1" update: Write Protect For Storage Disabled - Update logic by removing the reg string to also account for potential renamed executions update: Zip A Folder With PowerShell For Staging In Temp - PowerShell Module - Update logic to be more specific update: Zip A Folder With PowerShell For Staging In Temp - PowerShell - Update logic to be more specific update: Zip A Folder With PowerShell For Staging In Temp - PowerShell Script - Update logic to be more specific --------- Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>