f0e05ccb3c
- Added 5 more PowerShell scripts for the rule "file_event_win_powershell_exploit_scripts.yml" - Created new rule for "certoc" lolbin to cover "Download" option as described in the LOLBAS project - Created specific rule for the "IEExec" lolbin to cover "Download" option as described in the LOLBAS Project - Updated some rules to use "OriginalFileName" in addition to the "Image" selection - Updated some rules to increase coverage.
25 lines
652 B
YAML
25 lines
652 B
YAML
title: Ilasm Lolbin Use Compile C-Sharp
|
|
id: 850d55f9-6eeb-4492-ad69-a72338f65ba4
|
|
status: experimental
|
|
description: Detect use of Ilasm.exe to compile c# code into dll or exe.
|
|
references:
|
|
- https://lolbas-project.github.io/lolbas/Binaries/Ilasm/
|
|
- https://www.echotrail.io/insights/search/ilasm.exe
|
|
author: frack113
|
|
date: 2022/05/07
|
|
modified: 2022/05/16
|
|
logsource:
|
|
product: windows
|
|
category: process_creation
|
|
detection:
|
|
selection:
|
|
- Image|endswith: '\ilasm.exe'
|
|
- OriginalFileName: 'ilasm.exe'
|
|
condition: selection
|
|
falsepositives:
|
|
- Unknown
|
|
level: medium
|
|
tags:
|
|
- attack.defense_evasion
|
|
- attack.t1127
|