5483712805
* [New Rule] Lolbas ImageLoad via Windows Update Client * Update defense_evasion_execution_lolbas_wuauclt.toml * Update defense_evasion_execution_lolbas_wuauclt.toml * Update defense_evasion_execution_lolbas_wuauclt.toml * Update defense_evasion_execution_lolbas_wuauclt.toml * Update defense_evasion_execution_lolbas_wuauclt.toml * Update defense_evasion_execution_lolbas_wuauclt.toml * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update defense_evasion_execution_lolbas_wuauclt.toml * removed timeline_id * new eql synthax * Update defense_evasion_execution_lolbas_wuauclt.toml * ecs_version * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * removed new lines * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: dstepanic17 <57736958+dstepanic17@users.noreply.github.com> * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: dstepanic17 <57736958+dstepanic17@users.noreply.github.com> * Update rules/windows/defense_evasion_execution_lolbas_wuauclt.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * relinted * deleted ecs_version Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> Co-authored-by: dstepanic17 <57736958+dstepanic17@users.noreply.github.com>