Files
blue-team-tools/rules/windows/process_creation
xiangchen96 0376019001 Merge PR #4711 from @xiangchen96 - Fix some FP in Rundll32 Execution With Uncommon DLL Extension
update: Rundll32 Execution With Uncommon DLL Extension - Update the selection to allow for additional quoted cases such as rundll32 "shell32.dll",ShellExec_RunDLL <somethin>

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2024-02-08 16:11:32 +01:00
..