-
Notifications
You must be signed in to change notification settings - Fork 513
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Security Content] Add Windows Investigation Guides (#3095)
* [Security Content] Add Windows Investigation Guides * Update defense_evasion_rundll32_no_arguments.toml * Update persistence_suspicious_image_load_scheduled_task_ms_office.toml * Update privilege_escalation_posh_token_impersonation.toml * Apply suggestions from code review Co-authored-by: Ruben Groenewoud <[email protected]> * Update execution_ms_office_written_file.toml * Update persistence_suspicious_image_load_scheduled_task_ms_office.toml * Update rules/windows/defense_evasion_rundll32_no_arguments.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/defense_evasion_wsl_enabled_via_dism.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/defense_evasion_wsl_enabled_via_dism.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/defense_evasion_wsl_registry_modification.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/defense_evasion_wsl_registry_modification.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/execution_ms_office_written_file.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/persistence_suspicious_image_load_scheduled_task_ms_office.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/persistence_suspicious_image_load_scheduled_task_ms_office.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update rules/windows/persistence_via_wmi_stdregprov_run_services.toml Co-authored-by: Benjamin Ironside Goldstein <[email protected]> * Update privilege_escalation_posh_token_impersonation.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> Co-authored-by: Benjamin Ironside Goldstein <[email protected]> (cherry picked from commit eb7c5f6)
- Loading branch information
1 parent
837d166
commit bb36349
Showing
11 changed files
with
726 additions
and
44 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.