mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Remove dist directory from tracking
This commit is contained in:
Vendored
-7
@@ -1,7 +0,0 @@
|
||||
# Splunk ES Content Update
|
||||
|
||||
This subscription service delivers pre-packaged Security Content for use with Splunk Enterprise Security. Subscribers get regular updates to help security practitioners more quickly address ongoing and time-sensitive customer problems and threats.
|
||||
|
||||
Requires Splunk Enterprise Security version 4.5 or greater.
|
||||
|
||||
For more information please visit the [Splunk ES Content Update user documentation](https://docs.splunk.com/Documentation/ESSOC).
|
||||
@@ -1,15 +0,0 @@
|
||||
The Analytic Story Details dashboard renders all the details of the content related to a specific analytic story which
|
||||
can be chose via the drop down
|
||||
|
||||
Each analytic story has attributes associated with it and the following:
|
||||
______________________________________________________________________
|
||||
|
||||
|
||||
Analytic Story: name of the analytic story
|
||||
Description ; description of the analytic story
|
||||
Search Name : The name of the searches belonging to the chosen analytic story
|
||||
Search : The search query which looks for an attack pattern corresponding to the analytic story
|
||||
Search Description: The description of the search query
|
||||
Asset Type: The analytic story specifies what asset in the infrastructure may be compromised
|
||||
Category: The category that the search belongs to (malware, vulnerabilities, best practices, abuse)
|
||||
Kill Chain Phase: The kill chain phase of the attack that the search is after.
|
||||
@@ -1,24 +0,0 @@
|
||||
The ES_SOC Summary Dashboard provides you a summarized view of the analytic story contents of the ES-SOC app.
|
||||
The dashboard has the following panels gives you following details
|
||||
|
||||
1) Analytic story Summary
|
||||
- Total Analytic Stories : The total number of Analytic stories in the ES-SOC application
|
||||
- Total Searches: The total number of searches in ES-SOC
|
||||
- Searches added last week: Number of searches added to ES-SOC in the last week.
|
||||
|
||||
2) Analytic story Category: This dashboard panel summarizes the categories of the searches that the ES-SOC app contains. The categories of the analytic stories are as follow
|
||||
-Malware: These searches detect specific malware behavior for a particular phase of the attack kill chain. E.g. a malware’s delivery method via email or a malware’s installation behavior via registry key changes
|
||||
-Vulnerability: These searches detect behavior or a signature of a vulnerable software in use. These searches are not designed to replace vulnerability management or scanning systems. The purpose of these searches is to discover a vulnerability through side effects or behaviors.
|
||||
-Abuse: Some actions can be deemed malicious because they are unexpected, violate corporate policy or are significantly different than the actions of other users. E.g. A USB disk that is seen on multiple systems or a user that uploads excessive files to a cloud service or a database query that dumps an entire table
|
||||
-Best Practices: Searches that correspond to specific guidelines from organizations like SANS or OWASP
|
||||
|
||||
3) Kill Chain phases: Every analytic story has one or more searches which look for a certain kind of attack pattern/behavior. These searches have an attribute which essentially tells you what Kill chain phase does the search correspond to.
|
||||
The numbers on the dashboard represents the number of searches correponding to each kill chain phase
|
||||
|
||||
4) Analytic story table: This table gives the user a comprehensive view of some of the details of the analytic story. Some of the listed attributes are:
|
||||
- Analytic Story : The name of the analytic story
|
||||
- Description: The description of the analyttic story
|
||||
- Search names: The name of the searches in each analytic story
|
||||
- Datamodels: The name of the datamodel that the search is querying against.
|
||||
- Technology Examples: This field represent some examples related to the technologies required to populate the datamodels(Nessues, Cisco Firewall,etc)
|
||||
- Kill chain phase: The name of the kill chain phase that the search belongs to
|
||||
@@ -1,51 +0,0 @@
|
||||
######################
|
||||
ESSOC Usage Dashboard#
|
||||
######################
|
||||
|
||||
The ESSOC Usage dashboard is designed to provide high-level insight into the usage of the ES-SOC app. It is suitable for display when providing feedback to the Splunk team or for identifying how the ES-SOC app is being used. This dashboard has two time selectors that work independently - the top time selector determines the search time range for all the single-value. And the lower time selector, determines the time range for the usage table.
|
||||
|
||||
IMPORTANT: The user loading this dashboard must have permission to search the _audit index
|
||||
|
||||
##################
|
||||
#Dashboard panels#
|
||||
##################
|
||||
|
||||
Searches Ran
|
||||
|
||||
The total number of searches in ES-SOC that were executed. This number includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax
|
||||
|
||||
Unique Searches
|
||||
|
||||
The unique/distinct searches executed on the deployment. This is equivalent to the distinct count of searches run in the ES-SOC app.
|
||||
|
||||
Most Run
|
||||
|
||||
The total number of searches in ES-SOC that were executed. This number includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax.
|
||||
|
||||
Ad hoc Searches
|
||||
|
||||
The total number of searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax.
|
||||
|
||||
Scheduled
|
||||
|
||||
The total number of ESSOC searches run that were scheduled.
|
||||
|
||||
Most Active User
|
||||
|
||||
The user who executed the highest number/count of searches. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax.
|
||||
|
||||
Search Run Time (seconds)
|
||||
|
||||
Total run time of all searches executed in seconds. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax.
|
||||
|
||||
Average Run Time (seconds)
|
||||
|
||||
Average run time of all searches executed in seconds. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax.
|
||||
|
||||
Max Run Time (seconds)
|
||||
|
||||
The run time of the longest running search. This calculation includes scheduled searches and ad hoc searches run from the search bar using the '| savedsearch <ESSOC search_name> ‘ syntax.
|
||||
|
||||
Search summary
|
||||
|
||||
This table provides details on each search that was executed in the ESSOC app.
|
||||
-46
@@ -1,46 +0,0 @@
|
||||
{
|
||||
"schemaVersion": "1.0.0",
|
||||
"info": {
|
||||
"title": "ES Content Updates",
|
||||
"id": {
|
||||
"group": null,
|
||||
"name": "DA-ESS-ContentUpdate",
|
||||
"version": "4.35.0"
|
||||
},
|
||||
"author": [
|
||||
{
|
||||
"name": "Splunk Threat Research Team",
|
||||
"email": "research@splunk.com",
|
||||
"company": "Splunk"
|
||||
}
|
||||
],
|
||||
"releaseDate": "2024-07-01",
|
||||
"description": "Explore the Analytic Stories included with ES Content Updates.",
|
||||
"classification": {
|
||||
"intendedAudience": null,
|
||||
"categories": [],
|
||||
"developmentStatus": null
|
||||
},
|
||||
"commonInformationModels": null,
|
||||
"license": {
|
||||
"name": null,
|
||||
"text": null,
|
||||
"uri": null
|
||||
},
|
||||
"privacyPolicy": {
|
||||
"name": null,
|
||||
"text": null,
|
||||
"uri": null
|
||||
},
|
||||
"releaseNotes": {
|
||||
"name": null,
|
||||
"text": "./README.md",
|
||||
"uri": null
|
||||
}
|
||||
},
|
||||
"dependencies": null,
|
||||
"tasks": null,
|
||||
"inputGroups": null,
|
||||
"incompatibleApps": null,
|
||||
"platformRequirements": null
|
||||
}
|
||||
@@ -1,2 +0,0 @@
|
||||
### Deprecated since ESCU UI was deprecated and this conf file is no longer in use
|
||||
### Using one single file analyticstories.conf that will be used both by ES and ESCU
|
||||
-20000
File diff suppressed because one or more lines are too long
-41
@@ -1,41 +0,0 @@
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
## Splunk app configuration file
|
||||
|
||||
[install]
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 20240701174052
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
reload.usage_searches = simple
|
||||
reload.use_case_library = simple
|
||||
reload.correlationsearches = simple
|
||||
reload.analyticstories = simple
|
||||
reload.governance = simple
|
||||
reload.managed_configurations = simple
|
||||
reload.postprocess = simple
|
||||
reload.content-version = simple
|
||||
reload.es_investigations = simple
|
||||
|
||||
[launcher]
|
||||
author = Splunk
|
||||
version = 4.35.0
|
||||
description = Explore the Analytic Stories included with ES Content Updates.
|
||||
|
||||
[ui]
|
||||
is_visible = true
|
||||
label = ES Content Updates
|
||||
|
||||
[package]
|
||||
id = DA-ESS-ContentUpdate
|
||||
|
||||
|
||||
|
||||
-100
@@ -1,100 +0,0 @@
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
[api_call_by_user_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[cloud_instances_enough_data]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[k8s_container_network_io_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[k8s_container_network_io_ratio_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[k8s_process_resource_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[k8s_process_resource_ratio_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_api_calls_from_user_roles]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_aws_cross_account_activity]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_aws_regions]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_api_calls_per_user_role]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_compute_creations_by_user]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_compute_images]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_compute_instance_types]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_instance_modifications_by_user]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_provisioning_activity_sources]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_cloud_regions]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_gcp_storage_access_from_remote_ip]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_running_windows_services]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_S3_access_from_remote_ip]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[previously_seen_users_console_logins]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[s3_deletion_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[security_group_activity_baseline]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
[zoom_first_time_child_process]
|
||||
enforceTypes = false
|
||||
replicate = false
|
||||
|
||||
-11
@@ -1,11 +0,0 @@
|
||||
# deprecated please see gist: https://gist.github.com/d1vious/c4c2aae7fa7d5cbb1f24adc5f6303ac1
|
||||
#[dnstwist]
|
||||
#filename = dnstwist.py
|
||||
#chunked = true
|
||||
|
||||
# run story functionality has been moved to: https://github.com/splunk/analytic_story_execution'
|
||||
# [runstory]
|
||||
# filename = runstory.py
|
||||
# chunked = true
|
||||
# is_risky = true
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
[content-version]
|
||||
version = 4.35.0
|
||||
@@ -1,7 +0,0 @@
|
||||
<nav search_view="search" color="#65A637">
|
||||
<view name="escu_summary" default="true"/>
|
||||
<view name="feedback"/>
|
||||
<view name="search"/>
|
||||
<view name="dashboards"/>
|
||||
<a href="http://docs.splunk.com/Documentation/ESSOC">Docs</a>
|
||||
</nav>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| search `netbackup` dest=$dest$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`aws_cloudwatchlogs_eks` |rename sourceIPs{} as src_ip |search src_ip=$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(user.username) values(requestURI) values(verb) values(userAgent) by source annotations.authorization.k8s.io/decision src_ip</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`aws_securityhub_firehose` "findings{}.Resources{}.Type"=AWSEC2Instance | rex field=findings{}.Resources{}.Id .*instance/(?<instance>.*)| rename instance as dest| search dest = $dest$ |rename findings{}.* as * | rename Remediation.Recommendation.Text as Remediation | table dest Title ProductArn Description FirstObservedAt RecordState Remediation</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` | rename userIdentity.accessKeyId as accessKeyId| search accessKeyId=$accessKeyId$ | spath output=user path=userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, awsRegion, eventName, errorCode, errorMessage</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` | search user=$user$| table _time userIdentity.type userIdentity.userName userIdentity.arn aws_account_id src awsRegion eventName eventType</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`aws_description` | rename id as networkAclId | search networkAclId=$networkAclId$ | table id account_id vpc_id network_acl_entries{}.*</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`aws_config` resourceId=$resourceId$ | table _time ARN relationships{}.resourceType relationships{}.name relationships{}.resourceId configuration.privateIpAddresses{}.privateIpAddress configuration.privateIpAddresses{}.association.publicIp</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`aws_config` | rename resourceId as bucketName |search bucketName=$bucketName$ | table resourceCreationTime bucketName vendor_region action aws_account_id supplementaryConfiguration.AccessControlList</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`google_gcp_pubsub_message` | rename data.protoPayload.requestMetadata.callerIp as src_ip | search src_ip =$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(data.protoPayload.methodName) as method_names values(data.protoPayload.resourceName) as resource_name values(data.protoPayload.requestMetadata.callerSuppliedUserAgent) as http_user_agent values(data.protoPayload.authenticationInfo.principalEmail) as user values(data.protoPayload.status.message) by src_ip data.resource.labels.cluster_name data.resource.type</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` | iplocation sourceIPAddress | search City=$City$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, City, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` | iplocation sourceIPAddress | search Country=$Country$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, Country, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` | iplocation sourceIPAddress | search src_ip=$src_ip$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` | iplocation sourceIPAddress | search Region=$Region$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, Region, user, userName, userType, src_ip, awsRegion, eventName, errorCode</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`netbackup` COMPUTERNAME=$dest$ | rename COMPUTERNAME as dest, MESSAGE as signature | table _time, dest, signature</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Certificates.All_Certificates where All_Certificates.SSL.ssl_subject_common_name=*$domain$ by All_Certificates.dest All_Certificates.src All_Certificates.SSL.ssl_issuer_common_name All_Certificates.SSL.ssl_subject_common_name All_Certificates.SSL.ssl_hash | `drop_dm_object_name(All_Certificates)` | `drop_dm_object_name(SSL)` | rename ssl_subject_common_name as domain | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| search tag=dns src_ip=$src_ip$ dest_port=53 | streamstats time_window=1d count values(dest_ip) as dcip by src_ip | table date_mday src_ip dcip count | sort -count</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats allow_old_summaries=true sum(All_Traffic.bytes_out) as "bytes_out" sum(All_Traffic.bytes_in) as "bytes_in" from datamodel=Network_Traffic where nodename=All_Traffic All_Traffic.dest_port=53 by All_Traffic.src All_Traffic.dest| `drop_dm_object_name(All_Traffic)` | rename src as src_ip | rename dest as dest_ip | search src_ip=$src_ip$ | search dest_ip = $dest_ip | eval ratio = (bytes_out/bytes_in) | table ratio</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`aws_description` | dedup id sortby -_time |rename id as instanceId| search instanceId=$instanceId$ | spath output=tags path=tags | eval tags=mvzip(key,value," = "), ip_address=if((ip_address == "null"),private_ip_address,ip_address) | table id, tags.Name, aws_account_id, placement, instance_type, key_name, ip_address, launch_time, state, vpc_id, subnet_id, tags | rename aws_account_id as "Account ID", id as ID, instance_type as Type, ip_address as "IP Address", key_name as "Key Pair", launch_time as "Launch Time", placement as "Availability Zone", state as State, subnet_id as Subnet, "tags.Name" as Name, vpc_id as VPC</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` dest=$dest$ |rename userIdentity.arn as arn, responseElements.instancesSet.items{}.instanceId as dest, responseElements.instancesSet.items{}.privateIpAddress as privateIpAddress, responseElements.instancesSet.items{}.imageId as amiID, responseElements.instancesSet.items{}.architecture as architecture, responseElements.instancesSet.items{}.keyName as keyName | table arn, awsRegion, dest, architecture, privateIpAddress, amiID, keyName</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
Vendored
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| from datamodel Email.All_Email | search message_id=$message_id$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| from datamodel Email.All_Email | search src_user=$src_user$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.signature=DHCPREQUEST All_Sessions.src_mac= $src_mac$ by All_Sessions.src_ip All_Sessions.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>|tstats `security_content_summariesonly` values(All_Email.dest) as dest values(All_Email.recipient) as recepient min(_time) as firstTime max(_time) as lastTime count from datamodel=Email.All_Email by All_Email.src |`drop_dm_object_name(All_Email)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search src=$src$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`wineventlog_security` (signature_id=4718 OR signature_id=4717) dest=$dest$ | rename user as "Account Modified" | table _time, dest, "Account Modified", Access_Right, signature</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`wineventlog_security` (signature_id=4718 OR signature_id=4717) user=$user$ | rename user as "Account Modified" | table _time, dest, "Account Modified", Access_Right, signature</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| search `notable` | search dest=$dest$ | table _time, dest, rule_name, owner, priority, severity, status_description</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name("Processes")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` values(Filesystem.file_name) as file_name values(Filesystem.dest) as dest, values(Filesystem.process_name) as process_name from datamodel=Endpoint.Filesystem by Filesystem.dest Filesystem.process_name Filesystem.file_path, Filesystem.action, _time | `drop_dm_object_name(Filesystem)` | search dest=$dest$ | search process_name=$process_name$ | table _time, process_name, dest, action, file_name, file_path</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name("Processes")` | search process_name= $process_name$ | search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count min(_time) max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name Processes.user Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search dest=$dest$ | join dest type=inner [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Ports by Ports.process_id Ports.src Ports.dest_port | `drop_dm_object_name(Ports)` | search dest_port=$dest_port$ | rename src as dest]</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count min(_time) max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.parent_process Processes.process_name Processes.user Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search dest = $dest$ | join dest type=inner [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Ports where Ports.dest_port=53 by Ports.process_id Ports.src | `drop_dm_object_name(Ports)` | rename src as dest]</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`sysmon` EventCode>18 EventCode<22 | rename host as dest | search dest=$dest$| table _time, dest, user, Name, Operation, EventType, Type, Query, Consumer, Filter</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`stream_http` session_id = $session_id$ | stats values(url) values(http_user_agent) by src_ip status</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` vendor_region=$vendor_region$| rename requestParameters.instancesSet.items{}.instanceId as instanceId | stats values(eventName) by user instanceId vendor_region</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`cloudtrail` user=$user$ | table _time userIdentity.type userIdentity.userName userIdentity.arn aws_account_id src awsRegion eventName eventType </query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login dc(Authentication.dest) AS distinct_count_dest values(Authentication.dest) AS Authentication.dest values(Authentication.app) AS Authentication.app from datamodel=Authentication where Authentication.action=failure by Authentication.user | where distinct_count_dest > 1 | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | `drop_dm_object_name("Authentication")` | search user=$user$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| from datamodel Network_Traffic.All_Traffic | search src_ip=$src_ip$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`okta` app=$app$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`wineventlog_security` EventCode=4624 Logon_Type=9 AuthenticationPackageName=Negotiate | stats count earliest(_time) as first_login latest(_time) as last_login by src_user dest | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | search dest=$dest$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`wineventlog_security` EventCode=4768 OR EventCode=4769 | rex field=user "(?<new_user>[^\@]+)" | stats count BY new_user, dest, EventCode | stats max(count) AS max_count sum(count) AS sum_count BY new_user, dest| search dest=$dest$ | where sum_count/max_count!=2 | rename new_user AS user </query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login values(Authentication.dest) AS Authentication.dest values(Authentication.app) AS Authentication.app values(Authentication.action) AS Authentication.action from datamodel=Authentication where Authentication.action=success by _time, Authentication.user | bucket _time span=30d | stats count min(first_login) as first_login max(last_login) as last_login values(Authentication.dest) AS Authentication.dest by Authentication.user | where count=1 | where first_login >= relative_time(now(), "-30d") | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | `drop_dm_object_name("Authentication")` | search dest=$dest$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature_id=4624 Authentication.app=win:remote by Authentication.src Authentication.dest Authentication.app Authentication.user Authentication.signature Authentication.src_nt_domain | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name("Authentication")` | search dest=$dest$ | table firstTime lastTime src src_nt_domain dest user app count | sort count</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`stream_http` | search src_ip=$src_ip$ | search dest_ip=$dest_ip$ | eval cs_content_type_length = len(cs_content_type) | search cs_content_type_length > 100 | rex field="cs_content_type" (?<suspicious_strings>cmd.exe) | eval suspicious_strings_found=if(match(cs_content_type, "application"), "True", "False") | rename suspicious_strings_found AS "Suspicious Content-Type Found" | fields "Suspicious Content-Type Found", dest_ip, src_ip, suspicious_strings, cs_content_type, cs_content_type_length, url</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>`okta` user=$user$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
<!--
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
-->
|
||||
<panel>
|
||||
<table>
|
||||
<search>
|
||||
<query>| tstats `security_content_summariesonly` values(Web.url) as url from datamodel=Web by Web.src,Web.http_user_agent,Web.http_method | `drop_dm_object_name("Web")`| search http_method, "POST" | search src=$src$</query>
|
||||
</search>
|
||||
<option name="drilldown">cell</option>
|
||||
<option name="wrap">false</option>
|
||||
</table>
|
||||
</panel>
|
||||
@@ -1,401 +0,0 @@
|
||||
<dashboard version="2" theme="light">
|
||||
<label>ESCU - AppLocker</label>
|
||||
<description></description>
|
||||
<definition><![CDATA[
|
||||
{
|
||||
"dataSources": {
|
||||
"ds_search_1_new_new": {
|
||||
"type": "ds.search",
|
||||
"options": {
|
||||
"query": "`applocker` \n| spath input=UserData_Xml path=RuleAndFileData.PolicyName output=PolicyName\n| spath input=UserData_Xml path=RuleAndFileData.RuleId output=RuleId\n| spath input=UserData_Xml path=RuleAndFileData.RuleName output=RuleName\n| spath input=UserData_Xml path=RuleAndFileData.RuleSddl output=RuleSddl\n| spath input=UserData_Xml path=RuleAndFileData.TargetUser output=TargetUser\n| spath input=UserData_Xml path=RuleAndFileData.TargetProcessId output=TargetProcessId\n| spath input=UserData_Xml path=RuleAndFileData.FilePath output=FilePath\n| spath input=UserData_Xml path=RuleAndFileData.Fqbn output=Fqbn\n| spath input=UserData_Xml path=RuleAndFileData.TargetLogonId output=TargetLogonId\n| spath input=UserData_Xml path=RuleAndFileData.FullFilePath output=FullFilePath\n| search PolicyName=*\n| table PolicyName, RuleId, RuleName, RuleSddl, TargetUser, TargetProcessId, FilePath, Fqbn, TargetLogonId, FullFilePath _time",
|
||||
"queryParameters": {
|
||||
"earliest": "$global_time.earliest$",
|
||||
"latest": "$global_time.latest$"
|
||||
}
|
||||
}
|
||||
},
|
||||
"ds_search_1_new": {
|
||||
"type": "ds.search",
|
||||
"options": {
|
||||
"query": "`applocker`\n\n| eval EventType=case(\n EventCode==8000, \"PolicyApplicationFailure\",\n EventCode==8001, \"PolicyApplicationSuccess\",\n EventCode==8002, \"AllowedFileExecution\",\n EventCode==8003, \"AuditedFileExecution\",\n EventCode==8004, \"BlockedFileExecution\",\n EventCode==8005, \"AllowedScriptOrMSIExecution\",\n EventCode==8006, \"AuditedScriptOrMSIExecution\",\n EventCode==8007, \"BlockedScriptOrMSIExecution\",\n EventCode==8020, \"AllowedPackagedApp\",\n EventCode==8021, \"AuditedPackagedApp\",\n EventCode==8022, \"DisabledPackagedApp\",\n EventCode==8023, \"AllowedPackagedAppInstallation\",\n EventCode==8024, \"AuditedPackagedAppInstallation\",\n EventCode==8025, \"DisabledPackagedAppInstallation\",\n EventCode==8027, \"NoPackagedAppRule\"\n)\n| table _time, host, EventCode, EventType\n| stats values(EventType) values(EventCode) count by host",
|
||||
"queryParameters": {
|
||||
"earliest": "$global_time.earliest$",
|
||||
"latest": "$global_time.latest$"
|
||||
}
|
||||
},
|
||||
"name": "eventcodereview"
|
||||
},
|
||||
"ds_search_1": {
|
||||
"type": "ds.search",
|
||||
"options": {
|
||||
"query": "`applocker`\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| search PolicyName=$policyname$ EventCode=$eventcode$\n| stats values(host) AS dest by PolicyName, EventCode, Description, RuleId, RuleName, RuleSddl, TargetUser, TargetProcessId, FilePath, Fqbn, TargetLogonId, FullFilePath _time",
|
||||
"queryParameters": {
|
||||
"earliest": "$global_time.earliest$",
|
||||
"latest": "$global_time.latest$"
|
||||
}
|
||||
},
|
||||
"name": "policy_review"
|
||||
},
|
||||
"ds_YbLTfvcS": {
|
||||
"type": "ds.search",
|
||||
"options": {
|
||||
"query": "`applocker` EventCode IN (8007, 8004, 8022, 8025, 8029, 8040)\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| stats count",
|
||||
"queryParameters": {
|
||||
"earliest": "$global_time.earliest$",
|
||||
"latest": "$global_time.latest$"
|
||||
}
|
||||
},
|
||||
"name": "blocks"
|
||||
},
|
||||
"ds_h2Fcom6o": {
|
||||
"type": "ds.search",
|
||||
"options": {
|
||||
"query": "`applocker` EventCode IN (8003, 8006, 8021, 8024, 8039)\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| stats count"
|
||||
},
|
||||
"name": "Audit"
|
||||
},
|
||||
"ds_CAVvUpZ1": {
|
||||
"type": "ds.search",
|
||||
"options": {
|
||||
"query": "`applocker` EventCode IN (8002, 8005, 8020, 8023, 8033, 8037)\n| spath input=UserData_Xml | rename RuleAndFileData.* as *\n| lookup applockereventcodes EventCode OUTPUT Description\n| stats count",
|
||||
"queryParameters": {
|
||||
"earliest": "$global_time.earliest$",
|
||||
"latest": "$global_time.latest$"
|
||||
}
|
||||
},
|
||||
"name": "allowed"
|
||||
}
|
||||
},
|
||||
"visualizations": {
|
||||
"viz_table_1_new": {
|
||||
"type": "splunk.table",
|
||||
"options": {
|
||||
"count": 20,
|
||||
"dataOverlayMode": "none",
|
||||
"drilldown": "none",
|
||||
"percentagesRow": false,
|
||||
"rowNumbers": false,
|
||||
"totalsRow": false,
|
||||
"wrap": true
|
||||
},
|
||||
"dataSources": {
|
||||
"primary": "ds_search_1_new"
|
||||
},
|
||||
"title": "EventCode Analysis"
|
||||
},
|
||||
"viz_table_1": {
|
||||
"type": "splunk.table",
|
||||
"options": {
|
||||
"count": 20,
|
||||
"dataOverlayMode": "none",
|
||||
"drilldown": "none",
|
||||
"percentagesRow": false,
|
||||
"rowNumbers": false,
|
||||
"totalsRow": false,
|
||||
"wrap": true
|
||||
},
|
||||
"dataSources": {
|
||||
"primary": "ds_search_1"
|
||||
},
|
||||
"title": "Policy Review"
|
||||
},
|
||||
"viz_oDemj4wG": {
|
||||
"type": "splunk.markdown",
|
||||
"options": {
|
||||
"markdown": "## AppLocker Event Code Reference\n- `8000` - Policy Application Failure: Indicates a problem with applying the policy.\n- `8001` - Policy Application Success: The policy has been applied successfully.\n- `8002` - Allowed File Execution: A file was allowed to run.\n- `8003` - Audited File Execution: A file was executed and logged for audit purposes.\n- `8004` - Blocked File Execution: A file was blocked from running.\n- `8005` - Allowed Script Or MSI Execution: A script or MSI was allowed to run.\n- `8006` - Audited Script Or MSI Execution: A script or MSI was executed and logged for audit purposes.\n- `8007` - Blocked Script Or MSI Execution: A script or MSI was blocked from running.\n- `8020` - Allowed Packaged App: A packaged app was allowed to run.\n- `8021` - Audited Packaged App: A packaged app was executed and logged for audit purposes.\n- `8022` - Disabled Packaged App: A packaged app was disabled from running.\n- `8023` - Allowed Packaged App Installation: Installation of a packaged app was permitted.\n- `8024` - Audited Packaged App Installation: Installation of a packaged app was audited.\n- `8025` - Disabled Packaged App Installation: Installation of a packaged app was disabled.\n- `8027` - No Packaged App Rule: No applicable rule was found for a packaged app.\n"
|
||||
}
|
||||
},
|
||||
"viz_7L8xsZTg": {
|
||||
"type": "splunk.singlevalue",
|
||||
"title": "Blocks",
|
||||
"dataSources": {
|
||||
"primary": "ds_YbLTfvcS"
|
||||
}
|
||||
},
|
||||
"viz_hAZfweZe": {
|
||||
"type": "splunk.singlevalue",
|
||||
"dataSources": {
|
||||
"primary": "ds_h2Fcom6o"
|
||||
},
|
||||
"title": "Audit"
|
||||
},
|
||||
"viz_xEjz65IP": {
|
||||
"type": "splunk.singlevalue",
|
||||
"title": "Allowed",
|
||||
"dataSources": {
|
||||
"primary": "ds_CAVvUpZ1"
|
||||
}
|
||||
}
|
||||
},
|
||||
"inputs": {
|
||||
"input_global_trp": {
|
||||
"type": "input.timerange",
|
||||
"options": {
|
||||
"token": "global_time",
|
||||
"defaultValue": "-24h@h,now"
|
||||
},
|
||||
"title": "Global Time Range"
|
||||
},
|
||||
"input_7M6KtkjS": {
|
||||
"options": {
|
||||
"items": [
|
||||
{
|
||||
"label": "All",
|
||||
"value": "*"
|
||||
},
|
||||
{
|
||||
"label": "APPX",
|
||||
"value": "appx"
|
||||
},
|
||||
{
|
||||
"label": "SCRIPT",
|
||||
"value": "script"
|
||||
},
|
||||
{
|
||||
"label": "EXE",
|
||||
"value": "exe"
|
||||
},
|
||||
{
|
||||
"label": "DLL",
|
||||
"value": "dll"
|
||||
},
|
||||
{
|
||||
"label": "MSI",
|
||||
"value": "msi"
|
||||
}
|
||||
],
|
||||
"token": "policyname",
|
||||
"defaultValue": "*"
|
||||
},
|
||||
"title": "Select Policy Name",
|
||||
"type": "input.dropdown"
|
||||
},
|
||||
"input_q9ZwkL2y": {
|
||||
"options": {
|
||||
"items": [
|
||||
{
|
||||
"label": "All",
|
||||
"value": "*"
|
||||
},
|
||||
{
|
||||
"label": "8000",
|
||||
"value": "8000"
|
||||
},
|
||||
{
|
||||
"label": "8001",
|
||||
"value": "8001"
|
||||
},
|
||||
{
|
||||
"label": "8002",
|
||||
"value": "8002"
|
||||
},
|
||||
{
|
||||
"label": "8003",
|
||||
"value": "8003"
|
||||
},
|
||||
{
|
||||
"label": "8004",
|
||||
"value": "8004"
|
||||
},
|
||||
{
|
||||
"label": "8005",
|
||||
"value": "8005"
|
||||
},
|
||||
{
|
||||
"label": "8006",
|
||||
"value": "8006"
|
||||
},
|
||||
{
|
||||
"label": "8007",
|
||||
"value": "8007"
|
||||
},
|
||||
{
|
||||
"label": "8008",
|
||||
"value": "8008"
|
||||
},
|
||||
{
|
||||
"label": "8020",
|
||||
"value": "8020"
|
||||
},
|
||||
{
|
||||
"label": "8021",
|
||||
"value": "8021"
|
||||
},
|
||||
{
|
||||
"label": "8022",
|
||||
"value": "8022"
|
||||
},
|
||||
{
|
||||
"label": "8023",
|
||||
"value": "8023"
|
||||
},
|
||||
{
|
||||
"label": "8024",
|
||||
"value": "8024"
|
||||
},
|
||||
{
|
||||
"label": "8025",
|
||||
"value": "8025"
|
||||
},
|
||||
{
|
||||
"label": "8027",
|
||||
"value": "8027"
|
||||
},
|
||||
{
|
||||
"label": "8028",
|
||||
"value": "8028"
|
||||
},
|
||||
{
|
||||
"label": "8029",
|
||||
"value": "8029"
|
||||
},
|
||||
{
|
||||
"label": "8030",
|
||||
"value": "8030"
|
||||
},
|
||||
{
|
||||
"label": "8031",
|
||||
"value": "8031"
|
||||
},
|
||||
{
|
||||
"label": "8032",
|
||||
"value": "8032"
|
||||
},
|
||||
{
|
||||
"label": "8033",
|
||||
"value": "8033"
|
||||
},
|
||||
{
|
||||
"label": "8034",
|
||||
"value": "8034"
|
||||
},
|
||||
{
|
||||
"label": "8035",
|
||||
"value": "8035"
|
||||
},
|
||||
{
|
||||
"label": "8036",
|
||||
"value": "8036"
|
||||
},
|
||||
{
|
||||
"label": "8037",
|
||||
"value": "8037"
|
||||
},
|
||||
{
|
||||
"label": "8038",
|
||||
"value": "8038"
|
||||
},
|
||||
{
|
||||
"label": "8039",
|
||||
"value": "8039"
|
||||
},
|
||||
{
|
||||
"label": "8040",
|
||||
"value": "8040"
|
||||
}
|
||||
],
|
||||
"defaultValue": "*",
|
||||
"token": "eventcode"
|
||||
},
|
||||
"title": "Select EventCode",
|
||||
"type": "input.dropdown"
|
||||
}
|
||||
},
|
||||
"layout": {
|
||||
"type": "grid",
|
||||
"options": {
|
||||
"submitButton": true,
|
||||
"submitOnDashboardLoad": true
|
||||
},
|
||||
"structure": [
|
||||
{
|
||||
"item": "viz_oDemj4wG",
|
||||
"type": "block",
|
||||
"position": {
|
||||
"x": 0,
|
||||
"y": 0,
|
||||
"w": 1200,
|
||||
"h": 179
|
||||
}
|
||||
},
|
||||
{
|
||||
"item": "viz_7L8xsZTg",
|
||||
"type": "block",
|
||||
"position": {
|
||||
"x": 0,
|
||||
"y": 179,
|
||||
"w": 300,
|
||||
"h": 168
|
||||
}
|
||||
},
|
||||
{
|
||||
"item": "viz_table_1",
|
||||
"type": "block",
|
||||
"position": {
|
||||
"x": 0,
|
||||
"y": 347,
|
||||
"w": 1200,
|
||||
"h": 682
|
||||
}
|
||||
},
|
||||
{
|
||||
"item": "viz_table_1_new",
|
||||
"type": "block",
|
||||
"position": {
|
||||
"x": 0,
|
||||
"y": 1029,
|
||||
"w": 1200,
|
||||
"h": 736
|
||||
}
|
||||
},
|
||||
{
|
||||
"item": "viz_hAZfweZe",
|
||||
"type": "block",
|
||||
"position": {
|
||||
"x": 300,
|
||||
"y": 179,
|
||||
"w": 300,
|
||||
"h": 168
|
||||
}
|
||||
},
|
||||
{
|
||||
"item": "viz_xEjz65IP",
|
||||
"type": "block",
|
||||
"position": {
|
||||
"x": 600,
|
||||
"y": 179,
|
||||
"w": 600,
|
||||
"h": 168
|
||||
}
|
||||
}
|
||||
],
|
||||
"globalInputs": [
|
||||
"input_global_trp",
|
||||
"input_7M6KtkjS",
|
||||
"input_q9ZwkL2y"
|
||||
]
|
||||
},
|
||||
"title": "ESCU - AppLocker",
|
||||
"defaults": {
|
||||
"dataSources": {
|
||||
"ds.search": {
|
||||
"options": {
|
||||
"queryParameters": {
|
||||
"latest": "$global_time.latest$",
|
||||
"earliest": "$global_time.earliest$"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"description": "Utilize this dashboard to assist with auditing and monitoring Windows AppLocker events for your endpoints. Configure the applocker macro to use the AppLocker data source for populating the dashboard."
|
||||
}
|
||||
]]></definition>
|
||||
<meta type="hiddenElements"><![CDATA[
|
||||
{
|
||||
"hideEdit": false,
|
||||
"hideOpenInSearch": false,
|
||||
"hideExport": false
|
||||
}
|
||||
]]></meta>
|
||||
</dashboard>
|
||||
@@ -1,199 +0,0 @@
|
||||
<form theme="dark" version="1.1">
|
||||
<label>Content Library</label>
|
||||
<!-- Example uses stats transforming command -->
|
||||
<!-- This limits evnts passed to post-process search -->
|
||||
<title>Splunk Security Content</title>
|
||||
<search id="baseSS">
|
||||
<query>| rest /services/saved/searches splunk_server=local count=0 | search title="ESCU - *"</query>
|
||||
</search>
|
||||
<search id="baseAS">
|
||||
<query>| rest /services/configs/conf-analyticstories splunk_server=local count=0 |search eai:acl.app = "DA-ESS-ContentUpdate"</query>
|
||||
</search>
|
||||
<init>
|
||||
<set token="form.as_category">*</set>
|
||||
<set token="form.detection">*</set>
|
||||
<set token="form.as_story">*</set>
|
||||
<set token="form.as_attack_id">*</set>
|
||||
</init>
|
||||
<!-- Rows for Analytic Story Stats -->
|
||||
<!-- Rows for Analytic Story Table -->
|
||||
<!-- Rows for Search Stats -->
|
||||
<fieldset submitButton="false"></fieldset>
|
||||
<row>
|
||||
<panel>
|
||||
<html>
|
||||
<div style="background-color: #f8d7da; border: 1px solid #f5c6cb; border-radius: 5px; padding: 15px; margin-bottom: 20px;">
|
||||
<h2 style="color: #721c24; margin: 0;">
|
||||
<i class="icon-info-circle" style="margin-right: 10px;"></i>
|
||||
Explore Splunk Security Content using
|
||||
<a href="/app/SplunkEnterpriseSecuritySuite/ess_use_case_library" style="color: #721c24; text-decoration: underline;">Splunk Enterprise Security</a>
|
||||
</h2>
|
||||
</div>
|
||||
</html>
|
||||
</panel>
|
||||
</row>
|
||||
<row id="analytic_stories_header_stats">
|
||||
<panel>
|
||||
<single>
|
||||
<title>Total Analytic Stories</title>
|
||||
<search base="baseAS">
|
||||
<query> search title="analytic_story://*" |stats count</query>
|
||||
</search>
|
||||
<!-- post-process search -->
|
||||
<option name="colorBy">value</option>
|
||||
<option name="colorMode">block</option>
|
||||
<option name="drilldown">none</option>
|
||||
<option name="numberPrecision">0</option>
|
||||
<option name="showSparkline">1</option>
|
||||
<option name="showTrendIndicator">1</option>
|
||||
<option name="trendColorInterpretation">standard</option>
|
||||
<option name="trendDisplayMode">absolute</option>
|
||||
<option name="unitPosition">after</option>
|
||||
<option name="useColors">1</option>
|
||||
<option name="useThousandSeparators">1</option>
|
||||
<option name="rangeColors">["0x555","0x65a637"]</option>
|
||||
<option name="rangeValues">[0]</option>
|
||||
</single>
|
||||
</panel>
|
||||
<panel>
|
||||
<single>
|
||||
<title>Total Detections</title>
|
||||
<search base="baseSS">
|
||||
<query>stats count by action.correlationsearch.label| eventstats sum(count) as total_detection_count| fields total_detection_count</query>
|
||||
</search>
|
||||
<!-- post-process search -->
|
||||
<option name="colorBy">value</option>
|
||||
<option name="colorMode">block</option>
|
||||
<option name="drilldown">none</option>
|
||||
<option name="numberPrecision">0</option>
|
||||
<option name="showSparkline">1</option>
|
||||
<option name="showTrendIndicator">1</option>
|
||||
<option name="trendColorInterpretation">standard</option>
|
||||
<option name="trendDisplayMode">absolute</option>
|
||||
<option name="unitPosition">after</option>
|
||||
<option name="useColors">1</option>
|
||||
<option name="useThousandSeparators">1</option>
|
||||
<option name="rangeColors">["0x555","0x65a637"]</option>
|
||||
<option name="rangeValues">[0]</option>
|
||||
</single>
|
||||
</panel>
|
||||
<panel>
|
||||
<single>
|
||||
<title>ESCU App Version</title>
|
||||
<search id="version">
|
||||
<query>| rest /services/configs/conf-content-version splunk_server=local count=0 | table version</query>
|
||||
</search>
|
||||
<option name="colorBy">value</option>
|
||||
<option name="colorMode">block</option>
|
||||
<option name="drilldown">none</option>
|
||||
<option name="numberPrecision">0</option>
|
||||
<option name="rangeColors">["0x555","0x65a637"]</option>
|
||||
<option name="rangeValues">[0]</option>
|
||||
<option name="refresh.display">progressbar</option>
|
||||
<option name="showSparkline">1</option>
|
||||
<option name="showTrendIndicator">1</option>
|
||||
<option name="trendColorInterpretation">standard</option>
|
||||
<option name="trendDisplayMode">absolute</option>
|
||||
<option name="unitPosition">after</option>
|
||||
<option name="useColors">1</option>
|
||||
<option name="useThousandSeparators">1</option>
|
||||
</single>
|
||||
</panel>
|
||||
</row>
|
||||
<row id="analytic_stories_viz">
|
||||
<panel>
|
||||
<title>Story Categories</title>
|
||||
<chart>
|
||||
<search>
|
||||
<query>| rest /services/configs/conf-analyticstories splunk_server=local count=0 | search eai:acl.app = "DA-ESS-ContentUpdate"| search title="analytic_story://*"| stats count by category</query>
|
||||
</search>
|
||||
<drilldown>
|
||||
<set token="form.as_category">$click.value$</set>
|
||||
<set token="as_category" prefix=""" suffix=""">$click.value$</set>
|
||||
</drilldown>
|
||||
<option name="charting.chart">bar</option>
|
||||
<option name="charting.drilldown">all</option>
|
||||
<option name="charting.legend.placement">none</option>
|
||||
<option name="charting.axisLabelsX.integerUnits">true</option>
|
||||
<option name="charting.axisTitleX.visibility">collapsed</option>
|
||||
<option name="charting.axisTitleY.visibility">collapsed</option>
|
||||
</chart>
|
||||
</panel>
|
||||
<panel>
|
||||
<title>Analytic Stories by MITRE Technique ID</title>
|
||||
<chart>
|
||||
<search>
|
||||
<query>
|
||||
| rest /services/saved/searches splunk_server=local count=0 | search title="ESCU - *"
|
||||
| spath input=action.correlationsearch.annotations path=mitre_attack{} output="MITRE Technique ID"
|
||||
| spath input=action.correlationsearch.annotations path=analytic_story{} output=story_name
|
||||
| stats dc(story_name) as "Analytic Stories" by "MITRE Technique ID"
|
||||
</query>
|
||||
</search>
|
||||
<drilldown>
|
||||
<set token="form.as_attack_id">$click.value$</set>
|
||||
<set token="as_attack_id">$click.value$</set>
|
||||
</drilldown>
|
||||
<option name="charting.legend.placement">none</option>
|
||||
</chart>
|
||||
</panel>
|
||||
</row>
|
||||
<row id="analytic_stories_details_table">
|
||||
<panel>
|
||||
<input type="dropdown" token="story">
|
||||
<label>Analytic Story</label>
|
||||
<choice value="*">All</choice>
|
||||
<search>
|
||||
<latest>now</latest>
|
||||
<query>| rest /services/configs/conf-savedsearches splunk_server=local count=0
|
||||
| search action.escu.search_type = detection
|
||||
| spath input=action.correlationsearch.annotations path=analytic_story{} output="story"
|
||||
| mvexpand story
|
||||
| dedup story | fields story</query>
|
||||
</search>
|
||||
<fieldForLabel>story</fieldForLabel>
|
||||
<fieldForValue>story</fieldForValue>
|
||||
<default>*</default>
|
||||
<prefix>"</prefix>
|
||||
<suffix>"</suffix>
|
||||
<initialValue>*</initialValue>
|
||||
</input>
|
||||
<html>
|
||||
<input id="analytic_filter_clear" class="btn btn-primary" type="button" value="Clear All"/>
|
||||
</html>
|
||||
<table>
|
||||
<title>Analytic Story Details</title>
|
||||
<search>
|
||||
<query>| rest /services/configs/conf-savedsearches splunk_server=local count=0
|
||||
| search action.escu.search_type = detection
|
||||
| spath input=action.correlationsearch.annotations path=analytic_story{} output="analytic_story"
|
||||
| spath input=action.correlationsearch.annotations path=mitre_attack{} output="mitre_attack"
|
||||
| spath input=action.escu.data_models path={} output="Data Models"
|
||||
| rename title as "Detections"
|
||||
| join analytic_story
|
||||
[| rest /services/configs/conf-analyticstories splunk_server=local count=0
|
||||
| search title="analytic_story://*"
|
||||
| eval "analytic_story"=replace(title,"analytic_story://","" )
|
||||
]
|
||||
| search analytic_story= $story$
|
||||
|stats values(Detections) as Detections values(mitre_attack) as "MITRE Technique ID" values(last_updated) as "Last Updated" by analytic_story description| rename analytic_story as "Analytic Story"| rename description as Description| table "Analytic Story" Description Detections "MITRE Technique ID" "Last Updated"</query>
|
||||
<earliest>$earliest$</earliest>
|
||||
<latest>$latest$</latest>
|
||||
</search>
|
||||
<option name="count">5</option>
|
||||
<option name="dataOverlayMode">none</option>
|
||||
<option name="drilldown">row</option>
|
||||
<option name="refresh.display">progressbar</option>
|
||||
<option name="rowNumbers">true</option>
|
||||
<option name="wrap">true</option>
|
||||
<drilldown>
|
||||
<link target="_blank">
|
||||
<![CDATA[
|
||||
/app/SplunkEnterpriseSecuritySuite/ess_analytic_story_details?analytic_story=$row.Analytic Story$
|
||||
]]>
|
||||
</link>
|
||||
</drilldown>
|
||||
</table>
|
||||
</panel>
|
||||
</row>
|
||||
</form>
|
||||
@@ -1,13 +0,0 @@
|
||||
<form isVisible="true" version="1.1">
|
||||
<label>Feedback Center</label>
|
||||
<description>Welcome to Splunk Enterprise Security Content Updates Feedback Center.</description>
|
||||
<row>
|
||||
<panel>
|
||||
<html>
|
||||
<p5>Contact us at <a href = "mailto:research@splunk.com">research@splunk.com</a> to send us support requests, bug reports, or questions directly to the Splunk Security Research Team.
|
||||
<br>Please specify your request type and/or the title of any related Analytic Stories.</br>
|
||||
You can also find us in the <b>#security-research</b> room in the <a href = "http://splunk-usergroups.slack.com/">Splunk Slack channel</a></p5>
|
||||
</html>
|
||||
</panel>
|
||||
</row>
|
||||
</form>
|
||||
@@ -1,5 +0,0 @@
|
||||
[replicationSettings:refineConf]
|
||||
replicate.analytic_stories = false
|
||||
|
||||
[replicationDenylist]
|
||||
excludeESCU = apps[/\\]DA-ESS-ContentUpdate[/\\]lookups[/\\]...
|
||||
@@ -1,768 +0,0 @@
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
[panel://workbench_panel_all_backup_logs_for_host___response_task]
|
||||
label = All backup logs for host
|
||||
description = Retrieve the backup logs for the last 2 weeks for a specific host in order to investigate why backups are not completing successfully.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task]
|
||||
label = Amazon EKS Kubernetes activity by src ip
|
||||
description = This search provides investigation data about requests via user agent, authentication request URI, verb and cluster name data against Kubernetes cluster from a specific IP address
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task]
|
||||
label = AWS Investigate Security Hub alerts by dest
|
||||
description = This search retrieves the all the alerts created by AWS Security Hub for a specific dest(instance_id).
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_aws_investigate_user_activities_by_accesskeyid___response_task]
|
||||
label = AWS Investigate User Activities By AccessKeyId
|
||||
description = This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific credentials.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"accessKeyId": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR accessKeyId=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task]
|
||||
label = AWS Investigate User Activities By ARN
|
||||
description = This search lists all the logged CloudTrail activities by a specific user ARN and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and all the user's identity information.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"user": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR user=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "identity",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_aws_network_acl_details_from_id___response_task]
|
||||
label = AWS Network ACL Details from ID
|
||||
description = This search queries AWS description logs and returns all the information about a specific network ACL via network ACL ID
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"networkAclId": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR networkAclId=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task]
|
||||
label = AWS Network Interface details via resourceId
|
||||
description = This search queries AWS configuration logs and returns the information about a specific network interface via network interface ID. The information will include the ARN of the network interface, its relationships with other AWS resources, the public and the private IP associated with the network interface.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"resourceId": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR resourceId=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task]
|
||||
label = AWS S3 Bucket details via bucketName
|
||||
description = This search queries AWS configuration logs and returns the information about a specific S3 bucket. The information returned includes the time the S3 bucket was created, the resource ID, the region it belongs to, the value of action performed, AWS account ID, and configuration values of the access-control lists associated with the bucket.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"bucketName": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR bucketName=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task]
|
||||
label = GCP Kubernetes activity by src ip
|
||||
description = This search provides investigation data about requests via user agent, authentication request URI, resource path and cluster name data against Kubernetes cluster from a specific IP address
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_all_aws_activity_from_city___response_task]
|
||||
label = Get All AWS Activity From City
|
||||
description = This search retrieves all the activity from a specific city and will create a table containing the time, city, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"City": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR City=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_all_aws_activity_from_country___response_task]
|
||||
label = Get All AWS Activity From Country
|
||||
description = This search retrieves all the activity from a specific country and will create a table containing the time, country, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"Country": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR Country=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task]
|
||||
label = Get All AWS Activity From IP Address
|
||||
description = This search retrieves all the activity from a specific IP address and will create a table containing the time, ARN, username, the type of user, the IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_all_aws_activity_from_region___response_task]
|
||||
label = Get All AWS Activity From Region
|
||||
description = This search retrieves all the activity from a specific geographic region and will create a table containing the time, geographic region, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"Region": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR Region=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_backup_logs_for_endpoint___response_task]
|
||||
label = Get Backup Logs For Endpoint
|
||||
description = This search will tell you the backup status from your netbackup_logs of a specific endpoint for the last week.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_certificate_logs_for_a_domain___response_task]
|
||||
label = Get Certificate logs for a domain
|
||||
description = This search queries the Certificates datamodel and give you all the information for a specific domain. Please note that the certificates issued by "Let's Encrypt" are widely used by attackers.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"domain": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR domain=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_dns_server_history_for_a_host___response_task]
|
||||
label = Get DNS Server History for a host
|
||||
description = While investigating any detections it is important to understand which and how many DNS servers a host has connected to in the past. This search uses data that is tagged as DNS and gives you a count and list of DNS servers that a particular host has connected to the previous 24 hours.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_dns_traffic_ratio___response_task]
|
||||
label = Get DNS traffic ratio
|
||||
description = This search calculates the ratio of DNS traffic originating and coming from a host to a list of DNS servers over the last 24 hours. A high value of this ratio could be very useful to quickly understand if a src_ip (host) is sending a high volume of data out via port 53, could be an indicator of data exfiltration via DNS.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task]
|
||||
label = Get EC2 Instance Details by instanceId
|
||||
description = This search queries AWS description logs and returns all the information about a specific instance via the instanceId field
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"instanceId": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR instanceId=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_ec2_launch_details___response_task]
|
||||
label = Get EC2 Launch Details
|
||||
description = This search returns some of the launch details for a EC2 instance.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_email_info___response_task]
|
||||
label = Get Email Info
|
||||
description = This search returns all the information Splunk might have collected a specific email message over the last 2 hours.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"message_id": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR message_id=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_emails_from_specific_sender___response_task]
|
||||
label = Get Emails From Specific Sender
|
||||
description = This search returns all the emails from a specific sender over the last 24 and next hours.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_user": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_user=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address___response_task]
|
||||
label = Get First Occurrence and Last Occurrence of a MAC Address
|
||||
description = This search allows you to gather more context around a notable which has detected a new device connecting to your network. Use this search to determine the first and last occurrences of the suspicious device attempting to connect with your network.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_mac": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_mac=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_history_of_email_sources___response_task]
|
||||
label = Get History Of Email Sources
|
||||
description = This search returns a list of all email sources seen in the 48 hours prior to the notable event to 24 hours after, and the number of emails from each source.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_logon_rights_modifications_for_endpoint___response_task]
|
||||
label = Get Logon Rights Modifications For Endpoint
|
||||
description = This search allows you to retrieve any modifications to logon rights associated with a specific host.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_logon_rights_modifications_for_user___response_task]
|
||||
label = Get Logon Rights Modifications For User
|
||||
description = This search allows you to retrieve any modifications to logon rights for a specific user account.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"user": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR user=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "identity",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_notable_history___response_task]
|
||||
label = Get Notable History
|
||||
description = This search queries the notable index and returns all the Notable Events for the particular destination host, giving the analyst an overview of the incidents that may have occurred with the host under investigation.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_parent_process_info___response_task]
|
||||
label = Get Parent Process Info
|
||||
description = This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"parent_process_name": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR parent_process_name=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
},\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_process_file_activity___response_task]
|
||||
label = Get Process File Activity
|
||||
description = This search returns the file activity for a specific process on a specific endpoint
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
},\
|
||||
"process_name": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR process_name=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_process_info___response_task]
|
||||
label = Get Process Info
|
||||
description = This search queries the Endpoint data model to give you details about the process running on a host which is under investigation. To gather the process info, enter the values for the process name in question and the destination IP address.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"process_name": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR process_name=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
},\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_process_information_for_port_activity___response_task]
|
||||
label = Get Process Information For Port Activity
|
||||
description = This search will return information about the process associated with observed network traffic to a specific destination port from a specific host.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
},\
|
||||
"dest_port": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest_port=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task]
|
||||
label = Get Process Responsible For The DNS Traffic
|
||||
description = While investigating, an analyst will want to know what process and parent_process is responsible for generating suspicious DNS traffic. Use the following search and enter the value of `dest` in the search to get specific details on the process responsible for creating the DNS traffic.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task]
|
||||
label = Get Sysmon WMI Activity for Host
|
||||
description = This search queries Sysmon WMI events for the host of interest.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_get_web_session_information_via_session_id___response_task]
|
||||
label = Get Web Session Information via session id
|
||||
description = This search helps an analyst investigate a notable event to find out more about a specific web session. The search looks for a specific web session ID in the HTTP web traffic and outputs the URL and user agents, grouped by source IP address and HTTP status code.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"session_id": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR session_id=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_aws_activities_via_region_name___response_task]
|
||||
label = Investigate AWS activities via region name
|
||||
description = This search lists all the user activities logged by CloudTrail for a specific region in question and will create a table of the values of parameters requested, the type of the event and the response from the AWS API by each user
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"vendor_region": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR vendor_region=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_aws_user_activities_by_user_field___response_task]
|
||||
label = Investigate AWS User Activities by user field
|
||||
description = This search lists all the logged CloudTrail activities by a specific user and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and the user's identity information.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"user": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR user=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "identity",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task]
|
||||
label = Investigate Failed Logins for Multiple Destinations
|
||||
description = This search returns failed logins to multiple destinations by user.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"user": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR user=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "identity",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_network_traffic_from_src_ip___response_task]
|
||||
label = Investigate Network Traffic From src ip
|
||||
description = This search allows you to find all the network traffic from a specific IP address.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_okta_activity_by_app___response_task]
|
||||
label = Investigate Okta Activity by app
|
||||
description = This search returns all okta events associated with a specific app
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"app": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR app=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_pass_the_hash_attempts___response_task]
|
||||
label = Investigate Pass the Hash Attempts
|
||||
description = This search hunts for dumped NTLM hashes used for pass the hash.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_pass_the_ticket_attempts___response_task]
|
||||
label = Investigate Pass the Ticket Attempts
|
||||
description = This search hunts for dumped kerberos ticket from LSASS memory.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_previous_unseen_user___response_task]
|
||||
label = Investigate Previous Unseen User
|
||||
description = This search returns previous unseen user, which didn't log in for 30 days.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task]
|
||||
label = Investigate Successful Remote Desktop Authentications
|
||||
description = This search returns the source, destination, and user for all successful remote-desktop authentications. A successful authentication after a brute-force attack on a destination machine is suspicious behavior.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"dest": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "asset",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_suspicious_strings_in_http_header___response_task]
|
||||
label = Investigate Suspicious Strings in HTTP Header
|
||||
description = This search helps an analyst investigate a notable event related to a potential Apache Struts exploitation. To investigate, we will want to isolate and analyze the "payload" or the commands that were passed to the vulnerable hosts by creating a few regular expressions to carve out the commands focusing on common keywords from the payload, such as cmd.exe, /bin/bash and whois. The search returns these suspicious strings found in the HTTP logs of the system of interest.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
},\
|
||||
"dest_ip": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR dest_ip=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_user_activities_in_okta___response_task]
|
||||
label = Investigate User Activities In Okta
|
||||
description = This search returns all okta events by a specific user
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"user": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR user=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "identity",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
[panel://workbench_panel_investigate_web_posts_from_src___response_task]
|
||||
label = Investigate Web POSTs From src
|
||||
description = This investigative search retrieves POST requests from a specified source IP or hostname. Identifying the POST requests, as well as their associated destination URLs and user agent(s), may help you scope and characterize the suspicious traffic.
|
||||
disabled = 0
|
||||
tokens = {\
|
||||
"src": {\
|
||||
"valuePrefix": "\"",\
|
||||
"valueSuffix": "\"",\
|
||||
"delimiter": " OR src=",\
|
||||
"valueType": "primitive",\
|
||||
"value": "file",\
|
||||
"default": "null"\
|
||||
}\
|
||||
}\
|
||||
|
||||
|
||||
-7342
File diff suppressed because it is too large
Load Diff
-74128
File diff suppressed because it is too large
Load Diff
-486
@@ -1,486 +0,0 @@
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
[3cx_ioc_domains]
|
||||
filename = 3cx_ioc_domains.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of domains from the 3CX supply chain attack.
|
||||
match_type = WILDCARD(domain)
|
||||
min_matches = 1
|
||||
|
||||
[__mlspl_detect_dns_data_exfiltration_using_pretrained_model_in_dsdl]
|
||||
filename = __mlspl_detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.mlmodel
|
||||
case_sensitive_match = false
|
||||
# description = Detect DNS Data Exfiltration using pretrained Model in DSDL
|
||||
|
||||
[__mlspl_detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl]
|
||||
filename = __mlspl_detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.mlmodel
|
||||
case_sensitive_match = false
|
||||
# description = Detect suspicious DNS txt records using Pretrained Model in DSDL
|
||||
|
||||
[__mlspl_detect_suspicious_processnames_using_pretrained_model_in_dsdl]
|
||||
filename = __mlspl_detect_suspicious_processnames_using_pretrained_model_in_dsdl.mlmodel
|
||||
case_sensitive_match = false
|
||||
# description = Detect a suspicious processname using Pretrained Model in DSDL
|
||||
|
||||
[__mlspl_pretrained_dga_model_dsdl]
|
||||
filename = __mlspl_pretrained_dga_model_dsdl.mlmodel
|
||||
case_sensitive_match = false
|
||||
# description = Detect DGA domains using Pretrained Model in DSDL
|
||||
|
||||
[__mlspl_risky_spl_pre_trained_model]
|
||||
filename = __mlspl_risky_spl_pre_trained_model.mlmodel
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = Detect Risky SPL using Pretrained ML Model
|
||||
min_matches = 1
|
||||
|
||||
[__mlspl_unusual_commandline_detection]
|
||||
filename = __mlspl_unusual_commandline_detection.mlmodel
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = An MLTK model for detecting malicious commandlines
|
||||
min_matches = 1
|
||||
|
||||
[advanced_audit_policy_guids]
|
||||
filename = advanced_audit_policy_guids.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = List of GUIDs associated with Windows advanced audit policies
|
||||
match_type = WILDCARD(GUID)
|
||||
min_matches = 1
|
||||
|
||||
[api_call_by_user_baseline]
|
||||
collection = api_call_by_user_baseline
|
||||
external_type = kvstore
|
||||
# description = A collection that will contain the baseline information for number of AWS API calls per user
|
||||
fields_list = arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls
|
||||
|
||||
[applockereventcodes]
|
||||
filename = applockereventcodes.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A csv of the ID and rule name for AppLocker event codes.
|
||||
match_type = WILDCARD(AppLocker_Event_Code)
|
||||
min_matches = 1
|
||||
|
||||
[asr_rules]
|
||||
filename = asr_rules.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A csv of the ID and rule name for ASR, Microsoft Attack Surface Reduction rules.
|
||||
match_type = WILDCARD(ASR_Rule)
|
||||
min_matches = 1
|
||||
|
||||
[attacker_tools]
|
||||
filename = attacker_tools.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of tools used by attackers
|
||||
match_type = WILDCARD(attacker_tool_names)
|
||||
min_matches = 1
|
||||
|
||||
[aws_service_accounts]
|
||||
filename = aws_service_accounts.csv
|
||||
# description = A lookup file that will contain AWS Service accounts
|
||||
|
||||
[baseline_blocked_outbound_connections]
|
||||
filename = baseline_blocked_outbound_connections.csv
|
||||
# description = A lookup file that will contain the baseline information for number of blocked outbound connections
|
||||
|
||||
[brandMonitoring_lookup]
|
||||
filename = brand_monitoring.csv
|
||||
default_match = false
|
||||
# description = A file that contains look-a-like domains for brands that you want to monitor
|
||||
match_type = WILDCARD(domain)
|
||||
min_matches = 1
|
||||
|
||||
[browser_app_list]
|
||||
filename = browser_app_list.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of known browser application being targeted for credential extraction.
|
||||
match_type = WILDCARD(browser_process_name), WILDCARD(browser_object_path)
|
||||
min_matches = 1
|
||||
|
||||
[char_conversion_matrix]
|
||||
filename = char_conversion_matrix.csv
|
||||
default_match = false
|
||||
case_sensitive_match = true
|
||||
# description = A simple conversion matrix for converting to and from UTF8/16 base64/hex/decimal encoding. Created mosty from https://community.splunk.com/t5/Splunk-Search/base64-decoding-in-search/m-p/27572#M177741, with small modifications for UTF16LE parsing for powershell encoding.
|
||||
match_type = WILDCARD(data)
|
||||
min_matches = 1
|
||||
|
||||
[cloud_instances_enough_data]
|
||||
collection = cloud_instances_enough_data
|
||||
external_type = kvstore
|
||||
default_match = false
|
||||
# description = A lookup to determine if you have a sufficient amount of time has passed to collect cloud instance data for behavioral searches
|
||||
match_type = WILDCARD(filter)
|
||||
fields_list = _key, filter, enough_data
|
||||
|
||||
[discovered_dns_records]
|
||||
filename = discovered_dns_records.csv
|
||||
default_match = false
|
||||
# description = A placeholder for a list of discovered DNS records generated by the baseline discover_dns_records
|
||||
min_matches = 1
|
||||
|
||||
[domain_admins]
|
||||
filename = domain_admins.csv
|
||||
case_sensitive_match = false
|
||||
# description = List of domain admins
|
||||
|
||||
[domains]
|
||||
filename = domains.csv
|
||||
# description = A list of domains that can be ignored
|
||||
|
||||
[dynamic_dns_providers_default]
|
||||
filename = dynamic_dns_providers_default.csv
|
||||
case_sensitive_match = false
|
||||
# description = A list of dynammic dns providers that should not be modified
|
||||
match_type = WILDCARD(dynamic_dns_domains)
|
||||
|
||||
[dynamic_dns_providers_local]
|
||||
filename = dynamic_dns_providers_local.csv
|
||||
case_sensitive_match = false
|
||||
# description = A list of dynammic dns providers that can be modified
|
||||
match_type = WILDCARD(dynamic_dns_domains)
|
||||
|
||||
[hijacklibs]
|
||||
filename = hijacklibs.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of potentially abused libraries in Windows
|
||||
match_type = WILDCARD(library)
|
||||
min_matches = 1
|
||||
|
||||
[hijacklibs_loaded]
|
||||
filename = hijacklibs_loaded.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of potentially abused libraries in Windows
|
||||
match_type = WILDCARD(library),WILDCARD(excludes)
|
||||
min_matches = 1
|
||||
|
||||
[images_to_repository]
|
||||
filename = images_to_repository.csv
|
||||
# description = Mapping images to repositories
|
||||
|
||||
[is_net_windows_file]
|
||||
filename = is_net_windows_file20231221.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A full baseline of executable files in \Windows\, including sub-directories from Server 2016 and Windows 11. Certain .net binaries may not have been captured due to different Windows SDK's or developer utilities not installed during baseline.
|
||||
min_matches = 1
|
||||
|
||||
[is_nirsoft_software]
|
||||
filename = is_nirsoft_software20231221.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A subset of utilities provided by NirSoft that may be used by adversaries.
|
||||
min_matches = 1
|
||||
|
||||
[is_suspicious_file_extension_lookup]
|
||||
filename = is_suspicious_file_extension_lookup.csv
|
||||
# description = A list of suspicious extensions for email attachments
|
||||
match_type = WILDCARD(file_name)
|
||||
|
||||
[is_windows_system_file]
|
||||
filename = is_windows_system_file20231221.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A full baseline of executable files in Windows\System32 and Windows\Syswow64, including sub-directories from Server 2016 and Windows 10.
|
||||
min_matches = 1
|
||||
|
||||
[k8s_container_network_io_baseline]
|
||||
collection = k8s_container_network_io_baseline
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of used Kuberntes Container Network IO
|
||||
fields_list = key, avg_outbound_network_io, avg_inbound_network_io, stdev_outbound_network_io, stdev_inbound_network_io, count, last_seen
|
||||
|
||||
[k8s_container_network_io_ratio_baseline]
|
||||
collection = k8s_container_network_io_ratio_baseline
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of used Kuberntes Container Network IO Ratio
|
||||
fields_list = key, avg_outbound_network_io, avg_inbound_network_io, stdev_outbound_network_io, stdev_inbound_network_io, count, last_seen
|
||||
|
||||
[k8s_process_resource_baseline]
|
||||
collection = k8s_process_resource_baseline
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of used Kuberntes Process Resource
|
||||
fields_list = host.name, k8s.cluster.name, k8s.node.name, process.executable.name, avg_process.cpu.time, avg_process.cpu.utilization, avg_process.disk.io, avg_process.disk.operations, avg_process.memory.usage, avg_process.memory.utilization, avg_process.memory.virtual, avg_process.threads, stdev_process.cpu.time, stdev_process.cpu.utilization, stdev_process.disk.io, stdev_process.disk.operations, stdev_process.memory.usage, stdev_process.memory.utilization, stdev_process.memory.virtual, stdev_process.threads, key
|
||||
|
||||
[k8s_process_resource_ratio_baseline]
|
||||
collection = k8s_process_resource_ratio_baseline
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of used Kuberntes Process Ratios
|
||||
fields_list = key, avg_cpu:mem, stdev_cpu:mem, avg_cpu:disk, stdev_cpu:disk, avg_mem:disk, stdev_mem:disk, avg_cpu:threads, stdev_cpu:threads, avg_disk:threads, avg_disk:threads, count, last_seen
|
||||
|
||||
[legit_domains]
|
||||
filename = legit_domains.csv
|
||||
# description = A list of legit domains to be used as an ignore list for possible phishing sites
|
||||
|
||||
[linux_tool_discovery_process]
|
||||
filename = linux_tool_discovery_process.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of suspicious bash commonly used by attackers via scripts
|
||||
match_type = WILDCARD(process)
|
||||
min_matches = 1
|
||||
|
||||
[local_file_inclusion_paths]
|
||||
filename = local_file_inclusion_paths.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of interesting files in a local file inclusion attack
|
||||
match_type = WILDCARD(local_file_inclusion_paths)
|
||||
min_matches = 1
|
||||
|
||||
[lolbas_file_path]
|
||||
filename = lolbas_file_path.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of LOLBAS and their file path used in determining if a script or binary is valid on windows
|
||||
match_type = WILDCARD(lolbas_file_name)
|
||||
min_matches = 1
|
||||
|
||||
[loldrivers]
|
||||
filename = loldrivers.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of known vulnerable drivers
|
||||
match_type = WILDCARD(driver_name)
|
||||
min_matches = 1
|
||||
|
||||
[lookup_rare_process_allow_list_default]
|
||||
filename = rare_process_allow_list_default.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of rare processes that are legitimate that is provided by Splunk
|
||||
match_type = WILDCARD(process)
|
||||
min_matches = 1
|
||||
|
||||
[lookup_rare_process_allow_list_local]
|
||||
filename = rare_process_allow_list_local.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of rare processes that are legitimate provided by the end user
|
||||
match_type = WILDCARD(process)
|
||||
min_matches = 1
|
||||
|
||||
[lookup_uncommon_processes_default]
|
||||
filename = uncommon_processes_default.csv
|
||||
case_sensitive_match = false
|
||||
# description = A list of processes that are not common
|
||||
match_type = WILDCARD(process)
|
||||
|
||||
[lookup_uncommon_processes_local]
|
||||
filename = uncommon_processes_local.csv
|
||||
case_sensitive_match = false
|
||||
# description = A list of processes that are not common
|
||||
match_type = WILDCARD(process)
|
||||
|
||||
[mandatory_job_for_workflow]
|
||||
filename = mandatory_job_for_workflow.csv
|
||||
# description = A lookup file that will be used to define the mandatory job for workflow
|
||||
|
||||
[mandatory_step_for_job]
|
||||
filename = mandatory_step_for_job.csv
|
||||
# description = A lookup file that will be used to define the mandatory step for job
|
||||
|
||||
[network_acl_activity_baseline]
|
||||
filename = network_acl_activity_baseline.csv
|
||||
# description = A lookup file that will contain the baseline information for number of AWS Network ACL Activity
|
||||
|
||||
[previously_seen_api_calls_from_user_roles]
|
||||
collection = previously_seen_api_calls_from_user_roles
|
||||
external_type = kvstore
|
||||
# description = A placeholder for a list of IPs that have access S3
|
||||
fields_list = _key,earliest,latest,userName,eventName
|
||||
|
||||
[previously_seen_aws_cross_account_activity]
|
||||
collection = previously_seen_aws_cross_account_activity
|
||||
external_type = kvstore
|
||||
# description = A placeholder for a list of AWS accounts and assumed roles
|
||||
fields_list = _key,firstTime,lastTime,requestingAccountId,requestedAccountId
|
||||
|
||||
[previously_seen_aws_regions]
|
||||
collection = previously_seen_aws_regions
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of used AWS regions
|
||||
fields_list = _key,earliest,latest,awsRegion
|
||||
|
||||
[previously_seen_cloud_api_calls_per_user_role]
|
||||
collection = previously_seen_cloud_api_calls_per_user_role
|
||||
external_type = kvstore
|
||||
# description = A table of users, commands, and the first and last time that they have been seen
|
||||
fields_list = _key, user, command, firstTimeSeen, lastTimeSeen, enough_data
|
||||
|
||||
[previously_seen_cloud_compute_creations_by_user]
|
||||
collection = previously_seen_cloud_compute_creations_by_user
|
||||
external_type = kvstore
|
||||
# description = A table of previously seen users creating cloud instances
|
||||
fields_list = _key, firstTimeSeen, lastTimeSeen, user, enough_data
|
||||
|
||||
[previously_seen_cloud_compute_images]
|
||||
collection = previously_seen_cloud_compute_images
|
||||
external_type = kvstore
|
||||
# description = A table of previously seen Cloud image IDs
|
||||
fields_list = _key, firstTimeSeen, lastTimeSeen, image_id, enough_data
|
||||
|
||||
[previously_seen_cloud_compute_instance_types]
|
||||
collection = previously_seen_cloud_compute_instance_types
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of used cloud compute instance types
|
||||
fields_list = _key, firstTimeSeen, lastTimeSeen, instance_type, enough_data
|
||||
|
||||
[previously_seen_cloud_instance_modifications_by_user]
|
||||
collection = previously_seen_cloud_instance_modifications_by_user
|
||||
external_type = kvstore
|
||||
# description = A table of users seen making instance modifications, and the first and last time that the activity was observed
|
||||
fields_list = _key, firstTimeSeen, lastTimeSeen, user, enough_data
|
||||
|
||||
[previously_seen_cloud_provisioning_activity_sources]
|
||||
collection = previously_seen_cloud_provisioning_activity_sources
|
||||
external_type = kvstore
|
||||
# description = A table of source IPs, geographic locations, and the first and last time that they have that done cloud provisioning activities
|
||||
fields_list = _key, src, City, Country, Region, firstTimeSeen, lastTimeSeen, enough_data
|
||||
|
||||
[previously_seen_cloud_regions]
|
||||
collection = previously_seen_cloud_regions
|
||||
external_type = kvstore
|
||||
# description = A table of vendor_region values and the first and last time that they have been observed in cloud provisioning activities
|
||||
fields_list = _key, firstTimeSeen, lastTimeSeen, vendor_region, enough_data
|
||||
|
||||
[previously_seen_cmd_line_arguments]
|
||||
filename = previously_seen_cmd_line_arguments.csv
|
||||
# description = A placeholder for a list of cmd line arugments that been seen before
|
||||
|
||||
[previously_seen_ec2_modifications_by_user]
|
||||
filename = previously_seen_ec2_modifications_by_user.csv
|
||||
# description = A place holder for a list of AWS EC2 modifications done by each user
|
||||
|
||||
[previously_seen_gcp_storage_access_from_remote_ip]
|
||||
collection = previously_seen_gcp_storage_access_from_remote_ip
|
||||
external_type = kvstore
|
||||
# description = A place holder for a list of GCP storage access from remote IPs
|
||||
fields_list = _key, firstTime, lastTime, bucket_name, remote_ip, operation, request_uri
|
||||
|
||||
[previously_seen_running_windows_services]
|
||||
collection = previously_seen_running_windows_services
|
||||
external_type = kvstore
|
||||
# description = A placeholder for the list of Windows Services running
|
||||
fields_list = _key, service, firstTimeSeen, lastTimeSeen
|
||||
|
||||
[previously_seen_S3_access_from_remote_ip]
|
||||
collection = previously_seen_S3_access_from_remote_ip
|
||||
external_type = kvstore
|
||||
# description = A placeholder for a list of IPs that have access S3
|
||||
fields_list = _key, bucket_name,remote_ip,earliest,latest
|
||||
|
||||
[previously_seen_users_console_logins]
|
||||
collection = previously_seen_users_console_logins
|
||||
external_type = kvstore
|
||||
# description = A table of users seen doing console logins, and the first and last time that the activity was observed
|
||||
fields_list = _key, firstTime, lastTime, user, src, City, Region, Country
|
||||
|
||||
[privileged_azure_ad_roles]
|
||||
filename = privileged_azure_ad_roles.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of privileged Azure Active Directory roles.
|
||||
match_type = WILDCARD(azureadrole)
|
||||
min_matches = 1
|
||||
|
||||
[prohibited_apps_launching_cmd]
|
||||
filename = prohibited_apps_launching_cmd20231221.csv
|
||||
# description = A list of processes that should not be launching cmd.exe
|
||||
match_type = WILDCARD(prohibited_applications)
|
||||
|
||||
[prohibited_processes]
|
||||
filename = prohibited_processes.csv
|
||||
# description = A list of processes that have been marked as prohibited
|
||||
|
||||
[ransomware_extensions_lookup]
|
||||
filename = ransomware_extensions_20231219.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of file extensions that are associated with ransomware
|
||||
match_type = WILDCARD(Extensions)
|
||||
min_matches = 1
|
||||
|
||||
[ransomware_notes_lookup]
|
||||
filename = ransomware_notes_20231219.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of file names that are ransomware note files
|
||||
match_type = WILDCARD(ransomware_notes)
|
||||
min_matches = 1
|
||||
|
||||
[remote_access_software]
|
||||
filename = remote_access_software.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of Remote Access Software
|
||||
match_type = WILDCARD(remote_utility),WILDCARD(remote_domain),WILDCARD(remote_utility_fileinfo)
|
||||
min_matches = 1
|
||||
|
||||
[s3_deletion_baseline]
|
||||
collection = s3_deletion_baseline
|
||||
external_type = kvstore
|
||||
# description = A placeholder for the baseline information for AWS S3 deletions
|
||||
fields_list = _key, arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls
|
||||
|
||||
[security_group_activity_baseline]
|
||||
collection = security_group_activity_baseline
|
||||
external_type = kvstore
|
||||
# description = A placeholder for the baseline information for AWS security groups
|
||||
fields_list = _key, arn,latestCount,numDataPoints,avgApiCalls,stdevApiCalls
|
||||
|
||||
[security_services_lookup]
|
||||
filename = security_services.csv
|
||||
default_match = false
|
||||
# description = A list of services that deal with security
|
||||
match_type = WILDCARD(service)
|
||||
min_matches = 1
|
||||
|
||||
[splunk_risky_command]
|
||||
filename = splunk_risky_command_20240601.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of Risky Splunk Command that are candidates for abuse
|
||||
match_type = WILDCARD(splunk_risky_command)
|
||||
min_matches = 1
|
||||
|
||||
[suspicious_writes_lookup]
|
||||
filename = suspicious_files.csv
|
||||
default_match = false
|
||||
# description = A list of suspicious file names
|
||||
match_type = WILDCARD(file)
|
||||
min_matches = 1
|
||||
|
||||
[windows_protocol_handlers]
|
||||
filename = windows_protocol_handlers.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of Windows Protocol Handlers
|
||||
match_type = WILDCARD(handler)
|
||||
min_matches = 1
|
||||
|
||||
[zoom_first_time_child_process]
|
||||
collection = zoom_first_time_child_process
|
||||
external_type = kvstore
|
||||
# description = A list of suspicious file names
|
||||
fields_list = _key, dest, process_name, firstTimeSeen, lastTimeSeen
|
||||
|
||||
|
||||
### Default transforms definitions for the lookup files we ship ###
|
||||
[mitre_enrichment]
|
||||
filename = mitre_enrichment.csv
|
||||
# description = A lookup file that is created by generate.py
|
||||
@@ -1,73 +0,0 @@
|
||||
[escu-metrics-usage]
|
||||
action.email.useNSSubject = 1
|
||||
alert.digest_mode = True
|
||||
alert.suppress = 0
|
||||
alert.track = 0
|
||||
auto_summarize.dispatch.earliest_time = -1d@h
|
||||
dispatchAs = user
|
||||
search = index=_audit sourcetype="audittrail" \
|
||||
"ESCU - "\
|
||||
`comment("Find all the search names in the audittrail.")`\
|
||||
| stats count(search) by search savedsearch_name user\
|
||||
| eval usage=(if(savedsearch_name=="","Adhoc","Scheduled")) \
|
||||
`comment("If the savedsearch_name field in the audittrail is empty, the search was run adhoc. Otherwise it was run as a scheduled search")`\
|
||||
| rex field=search "\"(?<savedsearch_name>.*)\""\
|
||||
`comment("Extract the name of the search from the search string")`\
|
||||
| table savedsearch_name count(search) usage user | join savedsearch_name max=0 type=left [search sourcetype="manifests" | spath searches{} | mvexpand searches{} | spath input=searches{} | table category search_name | rename search_name as savedsearch_name | dedup savedsearch_name] | search category=*
|
||||
|
||||
[escu-metrics-search]
|
||||
action.email.useNSSubject = 1
|
||||
alert.suppress = 0
|
||||
alert.track = 0
|
||||
auto_summarize.dispatch.earliest_time = -1d@h
|
||||
enableSched = 1
|
||||
cron_schedule = 0 0 * * *
|
||||
dispatch.earliest_time = -4h@h
|
||||
dispatch.latest_time = -1h@h
|
||||
search = index=_audit action=search | transaction search_id maxspan=3m | search ESCU | stats sum(total_run_time) avg(total_run_time) max(total_run_time) sum(result_count)
|
||||
|
||||
[escu-metrics-search-events]
|
||||
action.email.useNSSubject = 1
|
||||
alert.digest_mode = True
|
||||
alert.suppress = 0
|
||||
alert.track = 0
|
||||
auto_summarize.dispatch.earliest_time = -1d@h
|
||||
cron_schedule = 0 0 * * *
|
||||
enableSched = 1
|
||||
dispatch.earliest_time = -4h@h
|
||||
dispatch.latest_time = -1h@h
|
||||
search = [search index=_audit sourcetype="audittrail" \"ESCU NOT "index=_audit" | where search !="" | dedup search_id | rex field=search "\"(?<search_name>.*)\"" | rex field=_raw "user=(?<user>[a-zA-Z0-9_\-]+)" | eval usage=if(savedsearch_name!="", "scheduled", "adhoc") | eval savedsearch_name=if(savedsearch_name != "", savedsearch_name, search_name) | table savedsearch_name search_id user _time usage | outputlookup escu_search_id.csv | table search_id] index=_audit total_run_time event_count result_count NOT "index=_audit" | lookup escu_search_id.csv search_id | stats count(savedsearch_name) AS search_count avg(total_run_time) AS search_avg_run_time sum(total_run_time) AS search_total_run_time sum(result_count) AS search_total_results earliest(_time) AS firsts latest(_time) AS lasts by savedsearch_name user usage| eval first_run=strftime(firsts, "%B %d %Y") | eval last_run=strftime(lasts, "%B %d %Y")
|
||||
|
||||
[escu-metrics-search-longest-runtime]
|
||||
action.email.useNSSubject = 1
|
||||
alert.digest_mode = True
|
||||
alert.suppress = 0
|
||||
alert.track = 0
|
||||
auto_summarize.dispatch.earliest_time = -1d@h
|
||||
enableSched = 1
|
||||
cron_schedule = 0 0 * * *
|
||||
disabled = 1
|
||||
dispatch.earliest_time = -4h@h
|
||||
dispatch.latest_time = -1h@h
|
||||
search = index=_* ESCU [search index=_* action=search latest=-2h earliest=-1d| transaction search_id maxspan=3m | search ESCU | stats values(total_run_time) AS run by search_id | sort -run | head 1| table search_id] | table search search_id
|
||||
|
||||
[escu-metrics-usage-search]
|
||||
action.email.useNSSubject = 1
|
||||
alert.digest_mode = True
|
||||
alert.suppress = 0
|
||||
alert.track = 0
|
||||
auto_summarize.dispatch.earliest_time = -1d@h
|
||||
cron_schedule = 0 0 * * *
|
||||
dispatch.earliest_time = -4h@h
|
||||
dispatch.latest_time = -1h@h
|
||||
enableSched = 1
|
||||
dispatchAs = user
|
||||
search = index=_audit sourcetype="audittrail" \
|
||||
"ESCU - "\
|
||||
`comment("Find all the search names in the audittrail. Ignore the last few minutes so we can exclude this search's text from the result.")`\
|
||||
| stats count(search) by search savedsearch_name user\
|
||||
| eval usage=(if(savedsearch_name=="","Adhoc","Scheduled")) \
|
||||
`comment("If the savedsearch_name field in the audittrail is empty, the search was run adhoc. Otherwise it was run as a scheduled search")`\
|
||||
| rex field=search "\"(?<savedsearch_name>.*)\""\
|
||||
`comment("Extract the name of the search from the search string")`\
|
||||
| table savedsearch_name count(search) usage user | join savedsearch_name max=0 type=left [search sourcetype="manifests" | spath searches{} | mvexpand searches{} | spath input=searches{} | table category search_name | rename search_name as savedsearch_name | dedup savedsearch_name] | search category=*
|
||||
@@ -1,2 +0,0 @@
|
||||
### Deprecated since ESCU UI was deprecated and this conf file is no longer in use
|
||||
### Using one single file analyticstories.conf that will be used both by ES and ESCU
|
||||
@@ -1,373 +0,0 @@
|
||||
#############
|
||||
# Automatically generated by 'contentctl build' from
|
||||
# https://github.com/splunk/contentctl
|
||||
# On Date: 2024-07-01T17:41:43 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
[workbench_panel_all_backup_logs_for_host___response_task]
|
||||
label = Workbench - All backup logs for host
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_all_backup_logs_for_host___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task]
|
||||
label = Workbench - Amazon EKS Kubernetes activity by src ip
|
||||
type = link
|
||||
fields = src_ip
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task]
|
||||
label = Workbench - AWS Investigate Security Hub alerts by dest
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_aws_investigate_user_activities_by_accesskeyid___response_task]
|
||||
label = Workbench - AWS Investigate User Activities By AccessKeyId
|
||||
type = link
|
||||
fields = accessKeyId
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_investigate_user_activities_by_accesskeyid___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_aws_investigate_user_activities_by_arn___response_task]
|
||||
label = Workbench - AWS Investigate User Activities By ARN
|
||||
type = link
|
||||
fields = user
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_aws_investigate_user_activities_by_arn___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_aws_network_acl_details_from_id___response_task]
|
||||
label = Workbench - AWS Network ACL Details from ID
|
||||
type = link
|
||||
fields = networkAclId
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_network_acl_details_from_id___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_aws_network_interface_details_via_resourceid___response_task]
|
||||
label = Workbench - AWS Network Interface details via resourceId
|
||||
type = link
|
||||
fields = resourceId
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_network_interface_details_via_resourceid___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_aws_s3_bucket_details_via_bucketname___response_task]
|
||||
label = Workbench - AWS S3 Bucket details via bucketName
|
||||
type = link
|
||||
fields = bucketName
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_aws_s3_bucket_details_via_bucketname___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task]
|
||||
label = Workbench - GCP Kubernetes activity by src ip
|
||||
type = link
|
||||
fields = src_ip
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_all_aws_activity_from_city___response_task]
|
||||
label = Workbench - Get All AWS Activity From City
|
||||
type = link
|
||||
fields = City
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_city___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_all_aws_activity_from_country___response_task]
|
||||
label = Workbench - Get All AWS Activity From Country
|
||||
type = link
|
||||
fields = Country
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_country___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_all_aws_activity_from_ip_address___response_task]
|
||||
label = Workbench - Get All AWS Activity From IP Address
|
||||
type = link
|
||||
fields = src_ip
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_ip_address___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_all_aws_activity_from_region___response_task]
|
||||
label = Workbench - Get All AWS Activity From Region
|
||||
type = link
|
||||
fields = Region
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_all_aws_activity_from_region___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_backup_logs_for_endpoint___response_task]
|
||||
label = Workbench - Get Backup Logs For Endpoint
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_backup_logs_for_endpoint___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_certificate_logs_for_a_domain___response_task]
|
||||
label = Workbench - Get Certificate logs for a domain
|
||||
type = link
|
||||
fields = domain
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_certificate_logs_for_a_domain___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_dns_server_history_for_a_host___response_task]
|
||||
label = Workbench - Get DNS Server History for a host
|
||||
type = link
|
||||
fields = src_ip
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_dns_server_history_for_a_host___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_dns_traffic_ratio___response_task]
|
||||
label = Workbench - Get DNS traffic ratio
|
||||
type = link
|
||||
fields = src_ip
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_dns_traffic_ratio___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_ec2_instance_details_by_instanceid___response_task]
|
||||
label = Workbench - Get EC2 Instance Details by instanceId
|
||||
type = link
|
||||
fields = instanceId
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_ec2_instance_details_by_instanceid___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_ec2_launch_details___response_task]
|
||||
label = Workbench - Get EC2 Launch Details
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_ec2_launch_details___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_email_info___response_task]
|
||||
label = Workbench - Get Email Info
|
||||
type = link
|
||||
fields = message_id
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_email_info___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_emails_from_specific_sender___response_task]
|
||||
label = Workbench - Get Emails From Specific Sender
|
||||
type = link
|
||||
fields = src_user
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_emails_from_specific_sender___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address___response_task]
|
||||
label = Workbench - Get First Occurrence and Last Occurrence of a MAC Address
|
||||
type = link
|
||||
fields = src_mac
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_history_of_email_sources___response_task]
|
||||
label = Workbench - Get History Of Email Sources
|
||||
type = link
|
||||
fields = src
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_history_of_email_sources___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_logon_rights_modifications_for_endpoint___response_task]
|
||||
label = Workbench - Get Logon Rights Modifications For Endpoint
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_logon_rights_modifications_for_endpoint___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_logon_rights_modifications_for_user___response_task]
|
||||
label = Workbench - Get Logon Rights Modifications For User
|
||||
type = link
|
||||
fields = user
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_get_logon_rights_modifications_for_user___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_notable_history___response_task]
|
||||
label = Workbench - Get Notable History
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_notable_history___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
[workbench_panel_get_process_responsible_for_the_dns_traffic___response_task]
|
||||
label = Workbench - Get Process Responsible For The DNS Traffic
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_process_responsible_for_the_dns_traffic___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_sysmon_wmi_activity_for_host___response_task]
|
||||
label = Workbench - Get Sysmon WMI Activity for Host
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_sysmon_wmi_activity_for_host___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_get_web_session_information_via_session_id___response_task]
|
||||
label = Workbench - Get Web Session Information via session id
|
||||
type = link
|
||||
fields = session_id
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_get_web_session_information_via_session_id___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_aws_activities_via_region_name___response_task]
|
||||
label = Workbench - Investigate AWS activities via region name
|
||||
type = link
|
||||
fields = vendor_region
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_aws_activities_via_region_name___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_aws_user_activities_by_user_field___response_task]
|
||||
label = Workbench - Investigate AWS User Activities by user field
|
||||
type = link
|
||||
fields = user
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_investigate_aws_user_activities_by_user_field___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task]
|
||||
label = Workbench - Investigate Failed Logins for Multiple Destinations
|
||||
type = link
|
||||
fields = user
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_network_traffic_from_src_ip___response_task]
|
||||
label = Workbench - Investigate Network Traffic From src ip
|
||||
type = link
|
||||
fields = src_ip
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_network_traffic_from_src_ip___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_okta_activity_by_app___response_task]
|
||||
label = Workbench - Investigate Okta Activity by app
|
||||
type = link
|
||||
fields = app
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_okta_activity_by_app___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_pass_the_hash_attempts___response_task]
|
||||
label = Workbench - Investigate Pass the Hash Attempts
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_pass_the_hash_attempts___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_pass_the_ticket_attempts___response_task]
|
||||
label = Workbench - Investigate Pass the Ticket Attempts
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_pass_the_ticket_attempts___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_previous_unseen_user___response_task]
|
||||
label = Workbench - Investigate Previous Unseen User
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_previous_unseen_user___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_successful_remote_desktop_authentications___response_task]
|
||||
label = Workbench - Investigate Successful Remote Desktop Authentications
|
||||
type = link
|
||||
fields = dest
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_successful_remote_desktop_authentications___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
|
||||
[workbench_panel_investigate_user_activities_in_okta___response_task]
|
||||
label = Workbench - Investigate User Activities In Okta
|
||||
type = link
|
||||
fields = user
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_identity=$@field_value$&panel=workbench_panel_investigate_user_activities_in_okta___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
[workbench_panel_investigate_web_posts_from_src___response_task]
|
||||
label = Workbench - Investigate Web POSTs From src
|
||||
type = link
|
||||
fields = src
|
||||
display_location = field_menu
|
||||
link.uri = /app/$@namespace$/ess_workbench_panel?type_asset=$@field_value$&panel=workbench_panel_investigate_web_posts_from_src___response_task&drilldown_field=$@field_name$&use_drilldown_time=true
|
||||
link.target = blank
|
||||
link.method = get
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
domain,isIOC,Description
|
||||
akamaicontainer.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
akamaitechcloudservices.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
azuredeploystore.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
azureonlinecloud.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
azureonlinestorage.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
dunamistrd.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
glcloudservice.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
journalide.org,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
msedgepackageinfo.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
msstorageazure.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
msstorageboxes.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
officeaddons.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
officestoragebox.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
pbxcloudeservices.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
pbxphonenetwork.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
pbxsources.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
qwepoi123098.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
sbmsa.wiki,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
sourceslabs.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
visualstudiofactory.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
zacharryblogs.com,TRUE,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
www.3cx.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
akamaitechcloudservices.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
azureonlinestorage.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
msedgepackageinfo.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
glcloudservice.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
pbxsources.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
msstorageazure.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
officestoragebox.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
visualstudiofactory.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
azuredeploystore.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
msstorageboxes.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
officeaddons.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
sourceslabs.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
zacharryblogs.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
pbxcloudeservices.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
pbxphonenetwork.com,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
msedgeupdate.net,TRUE,https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
|
-2
@@ -1,2 +0,0 @@
|
||||
algo,model,options
|
||||
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:62645"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl""}, ""args"": [""is_exfiltration"", ""src"", ""query"", ""rank""], ""target_variable"": [""is_exfiltration""], ""feature_variables"": [""src"", ""query"", ""rank""], ""model_name"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""src"", ""query"", ""rank""], ""target_variable"": ""is_exfiltration""}}","{""params"": {""mode"": ""stage"", ""algo"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl""}, ""args"": [""is_exfiltration"", ""src"", ""query"", ""rank""], ""target_variable"": [""is_exfiltration""], ""feature_variables"": [""src"", ""query"", ""rank""], ""model_name"": ""detect_dns_data_exfiltration_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
|
||||
-2
@@ -1,2 +0,0 @@
|
||||
algo,model,options
|
||||
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:54270"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl""}, ""args"": [""is_unknown"", ""text""], ""target_variable"": [""is_unknown""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""text""], ""target_variable"": ""is_unknown""}}","{""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl""}, ""args"": [""is_unknown"", ""text""], ""target_variable"": [""is_unknown""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
|
||||
-2
@@ -1,2 +0,0 @@
|
||||
algo,model,options
|
||||
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:58216"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl""}, ""args"": [""label"", ""text""], ""target_variable"": [""label""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""text""], ""target_variable"": ""label""}}","{""params"": {""mode"": ""stage"", ""algo"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl""}, ""args"": [""label"", ""text""], ""target_variable"": [""label""], ""feature_variables"": [""text""], ""model_name"": ""detect_suspicious_processnames_using_pretrained_model_in_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
|
||||
@@ -1,2 +0,0 @@
|
||||
algo,model,options
|
||||
MLTKContainer,"{""__mlspl_type"": [""mltkc.MLTKContainer"", ""MLTKContainer""], ""dict"": {""endpoint_url"": ""https://localhost:53378"", ""out_params"": {""params"": {""mode"": ""stage"", ""algo"": ""pretrained_dga_model_dsdl""}, ""args"": [""is_dga"", ""domain""], ""target_variable"": [""is_dga""], ""feature_variables"": [""domain""], ""model_name"": ""pretrained_dga_model_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}, ""feature_variables"": [""domain""], ""target_variable"": ""is_dga""}}","{""params"": {""mode"": ""stage"", ""algo"": ""pretrained_dga_model_dsdl""}, ""args"": [""is_dga"", ""domain""], ""target_variable"": [""is_dga""], ""feature_variables"": [""domain""], ""model_name"": ""pretrained_dga_model_dsdl"", ""algo_name"": ""MLTKContainer"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""4000"", ""max_model_size_mb"": ""30"", ""max_score_time"": ""600"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
|
||||
@@ -1,2 +0,0 @@
|
||||
algo,model,options
|
||||
DetectRiskySPL,"{""__mlspl_type"": [""algos.DetectRiskySPL"", ""DetectRiskySPL""], ""dict"": {""classes"": null, ""target_variable"": [""risk_score""], ""feature_variables"": [""spl_text""], ""columns"": [""spl_text""], ""estimator"": {""__mlspl_type"": [""sklearn.pipeline"", ""Pipeline""], ""dict"": {""steps"": [[""features"", {""__mlspl_type"": [""sklearn.feature_extraction.text"", ""CountVectorizer""], ""dict"": {""input"": ""content"", ""encoding"": ""utf-8"", ""decode_error"": ""strict"", ""strip_accents"": null, ""preprocessor"": null, ""tokenizer"": null, ""analyzer"": ""word"", ""lowercase"": true, ""token_pattern"": "" collect | delete | fit | outputcsv | outputlookup |adhoc| sendalert | sendemail |splunk\\-system\\-user| tscollect | run | script | runshellscript "", ""stop_words"": null, ""max_df"": 1.0, ""min_df"": 1, ""max_features"": null, ""ngram_range"": [1, 1], ""vocabulary"": null, ""binary"": false, ""dtype"": {""__mlspl_type"": [""builtins"", ""type""], ""type"": [""numpy"", ""int64""]}, ""fixed_vocabulary_"": false, ""_stop_words_id"": 94300723879360, ""stop_words_"": {""__mlspl_type"": [""builtins"", ""set""], ""set"": []}, ""vocabulary_"": {""splunk-system-user"": 12, "" delete "": 1, ""adhoc"": 11, "" outputlookup "": 4, "" script "": 7, "" run "": 5, "" collect "": 0, "" sendemail "": 9, "" sendalert "": 8, "" outputcsv "": 3, "" fit "": 2, "" runshellscript "": 6, "" tscollect "": 10}}}], [""predictor"", {""__mlspl_type"": [""sklearn.linear_model._logistic"", ""LogisticRegression""], ""dict"": {""penalty"": ""l2"", ""dual"": false, ""tol"": 0.0001, ""C"": 1.0, ""fit_intercept"": true, ""intercept_scaling"": 1, ""class_weight"": {""0"": 1, ""1"": 10}, ""random_state"": null, ""solver"": ""liblinear"", ""max_iter"": 100, ""multi_class"": ""auto"", ""verbose"": 0, ""warm_start"": false, ""n_jobs"": null, ""l1_ratio"": null, ""n_features_in_"": 13, ""classes_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGk4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDIsKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAoAAAAAAAAAAAEAAAAAAAAA""}, ""coef_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGY4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDEsIDEzKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAqulbT8VG8TQJU6VfC9QuY/kCCmapJVFUDQl14TS2ApPw5vYc32jBxAxVuQ3Sv35D8Y+azG/kDmP9vpUE0rTwlALsMVcoUGE0ASjjFaKyMaQA2zZ/yMQRZAQLZHc97OHEAfrzTDBGwSwA==""}, ""intercept_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGY4JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDEsKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAqBnhyKtBckwA==""}, ""n_iter_"": {""__mlspl_type"": [""numpy"", ""ndarray""], ""npy"": ""k05VTVBZAQB2AHsnZGVzY3InOiAnPGk0JywgJ2ZvcnRyYW5fb3JkZXInOiBGYWxzZSwgJ3NoYXBlJzogKDEsKSwgfSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAoLAAAA""}}}]], ""memory"": null, ""verbose"": false}}}}","{""args"": [""risk_score"", ""spl_text""], ""target_variable"": [""risk_score""], ""feature_variables"": [""spl_text""], ""model_name"": ""risky_spl_pre_trained_model"", ""algo_name"": ""LogisticRegression"", ""mlspl_limits"": {""handle_new_cat"": ""default"", ""max_distinct_cat_values"": ""100"", ""max_distinct_cat_values_for_classifiers"": ""100"", ""max_distinct_cat_values_for_scoring"": ""100"", ""max_fit_time"": ""600"", ""max_inputs"": ""100000"", ""max_memory_usage_mb"": ""1024"", ""max_model_size_mb"": ""15"", ""max_score_time"": ""600"", ""streaming_apply"": ""false"", ""use_sampling"": ""true""}, ""kfold_cv"": null}"
|
||||
-2
File diff suppressed because one or more lines are too long
@@ -1,69 +0,0 @@
|
||||
Category,SubCategory,GUID
|
||||
System,,{69979848-797A-11D9-BED3-505054503030}
|
||||
System,Security State Change,{0CCE9210-69AE-11D9-BED3-505054503030}
|
||||
System,Security System Extension,{0CCE9211-69AE-11D9-BED3-505054503030}
|
||||
System,System Integrity,{0CCE9212-69AE-11D9-BED3-505054503030}
|
||||
System,IPsec Driver,{0CCE9213-69AE-11D9-BED3-505054503030}
|
||||
System,Other System Events,{0CCE9214-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,,{69979849-797A-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Logon,{0CCE9215-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Logoff,{0CCE9216-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Account Lockout,{0CCE9217-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,IPsec Main Mode,{0CCE9218-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,IPsec Quick Mode,{0CCE9219-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,IPsec Extended Mode,{0CCE921A-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Special Logon,{0CCE921B-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Other Logon/Logoff Events,{0CCE921C-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Network Policy Server,{0CCE9243-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,User / Device Claims,{0CCE9247-69AE-11D9-BED3-505054503030}
|
||||
Logon/Logoff,Group Membership,{0CCE9249-69AE-11D9-BED3-505054503030}
|
||||
Object Access,,{6997984A-797A-11D9-BED3-505054503030}
|
||||
Object Access,File System,{0CCE921D-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Registry,{0CCE921E-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Kernel Object,{0CCE921F-69AE-11D9-BED3-505054503030}
|
||||
Object Access,SAM,{0CCE9220-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Certification Services,{0CCE9221-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Application Generated,{0CCE9222-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Handle Manipulation,{0CCE9223-69AE-11D9-BED3-505054503030}
|
||||
Object Access,File Share,{0CCE9224-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Filtering Platform Packet Drop,{0CCE9225-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Filtering Platform Connection,{0CCE9226-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Other Object Access Events,{0CCE9227-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Detailed File Share,{0CCE9244-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Removable Storage,{0CCE9245-69AE-11D9-BED3-505054503030}
|
||||
Object Access,Central Policy Staging,{0CCE9246-69AE-11D9-BED3-505054503030}
|
||||
Privilege Use,,{6997984B-797A-11D9-BED3-505054503030}
|
||||
Privilege Use,Sensitive Privilege Use,{0CCE9228-69AE-11D9-BED3-505054503030}
|
||||
Privilege Use,Non Sensitive Privilege Use,{0CCE9229-69AE-11D9-BED3-505054503030}
|
||||
Privilege Use,Other Privilege Use Events,{0CCE922A-69AE-11D9-BED3-505054503030}
|
||||
Detailed Tracking,,{6997984C-797A-11D9-BED3-505054503030}
|
||||
Detailed Tracking,Process Creation,{0CCE922B-69AE-11D9-BED3-505054503030}
|
||||
Detailed Tracking,Process Termination,{0CCE922C-69AE-11D9-BED3-505054503030}
|
||||
Detailed Tracking,DPAPI Activity,{0CCE922D-69AE-11D9-BED3-505054503030}
|
||||
Detailed Tracking,RPC Events,{0CCE922E-69AE-11D9-BED3-505054503030}
|
||||
Detailed Tracking,Plug and Play Events,{0CCE9248-69AE-11D9-BED3-505054503030}
|
||||
Detailed Tracking,Token Right Adjusted Events,{0CCE924A-69AE-11D9-BED3-505054503030}
|
||||
Policy Change,,{6997984D-797A-11D9-BED3-505054503030}
|
||||
Policy Change,Audit Policy Change,{0CCE922F-69AE-11D9-BED3-505054503030}
|
||||
Policy Change,Authentication Policy Change,{0CCE9230-69AE-11D9-BED3-505054503030}
|
||||
Policy Change,Authorization Policy Change,{0CCE9231-69AE-11D9-BED3-505054503030}
|
||||
Policy Change,MPSSVC Rule-Level Policy Change,{0CCE9232-69AE-11D9-BED3-505054503030}
|
||||
Policy Change,Filtering Platform Policy Change,{0CCE9233-69AE-11D9-BED3-505054503030}
|
||||
Policy Change,Other Policy Change Events,{0CCE9234-69AE-11D9-BED3-505054503030}
|
||||
Account Management,,{6997984E-797A-11D9-BED3-505054503030}
|
||||
Account Management,User Account Management,{0CCE9235-69AE-11D9-BED3-505054503030}
|
||||
Account Management,Computer Account Management,{0CCE9236-69AE-11D9-BED3-505054503030}
|
||||
Account Management,Security Group Management,{0CCE9237-69AE-11D9-BED3-505054503030}
|
||||
Account Management,Distribution Group Management,{0CCE9238-69AE-11D9-BED3-505054503030}
|
||||
Account Management,Application Group Management,{0CCE9239-69AE-11D9-BED3-505054503030}
|
||||
Account Management,Other Account Management Events,{0CCE923A-69AE-11D9-BED3-505054503030}
|
||||
DS Access,,{6997984F-797A-11D9-BED3-505054503030}
|
||||
DS Access,Directory Service Access,{0CCE923B-69AE-11D9-BED3-505054503030}
|
||||
DS Access,Directory Service Changes,{0CCE923C-69AE-11D9-BED3-505054503030}
|
||||
DS Access,Directory Service Replication,{0CCE923D-69AE-11D9-BED3-505054503030}
|
||||
DS Access,Detailed Directory Service Replication,{0CCE923E-69AE-11D9-BED3-505054503030}
|
||||
Account Logon,,{69979850-797A-11D9-BED3-505054503030}
|
||||
Account Logon,Credential Validation,{0CCE923F-69AE-11D9-BED3-505054503030}
|
||||
Account Logon,Kerberos Service Ticket Operations,{0CCE9240-69AE-11D9-BED3-505054503030}
|
||||
Account Logon,Other Account Logon Events,{0CCE9241-69AE-11D9-BED3-505054503030}
|
||||
Account Logon,Kerberos Authentication Service,{0CCE9242-69AE-11D9-BED3-505054503030}
|
||||
|
@@ -1,30 +0,0 @@
|
||||
EventCode, Description
|
||||
8000, AppID policy conversion failed. Status * <%1> * Indicates that the policy wasn't applied correctly to the computer. The status message is provided for troubleshooting purposes.
|
||||
8001, The AppLocker policy was applied successfully to this computer. Indicates that the AppLocker policy was successfully applied to the computer.
|
||||
8002, *<File name> * was allowed to run. Indicates an AppLocker rule allowed the .exe or .dll file.
|
||||
8003, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Shown only when the Audit only enforcement mode is enabled. Indicates that the AppLocker policy would block the .exe or .dll file if the enforcement mode setting was Enforce rules.
|
||||
8004, *<File name> * was prevented from running. AppLocker blocked the named EXE or DLL file. Shown only when the Enforce rules enforcement mode is enabled.
|
||||
8005, *<File name> * was allowed to run. Indicates an AppLocker rule allowed the script or .msi file.
|
||||
8006, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Shown only when the Audit only enforcement mode is enabled. Indicates that the AppLocker policy would block the script or .msi file if the Enforce rules enforcement mode was enabled.
|
||||
8007, *<File name> * was prevented from running. AppLocker blocked the named Script or MSI. Shown only when the Enforce rules enforcement mode is enabled.
|
||||
8008, *<File name> *: AppLocker component not available on this SKU. Indicates an edition of Windows that doesn't support AppLocker.
|
||||
8020, *<File name> * was allowed to run. Added in Windows Server 2012 and Windows 8.
|
||||
8021, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Added in Windows Server 2012 and Windows 8.
|
||||
8022, *<File name> * was prevented from running. Added in Windows Server 2012 and Windows 8.
|
||||
8023, *<File name> * was allowed to be installed. Added in Windows Server 2012 and Windows 8.
|
||||
8024, *<File name> * was allowed to run but would have been prevented from running if the AppLocker policy were enforced. Added in Windows Server 2012 and Windows 8.
|
||||
8025, *<File name> * was prevented from running. Added in Windows Server 2012 and Windows 8.
|
||||
8027, No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured. Added in Windows Server 2012 and Windows 8.
|
||||
8028, *<File name> * was allowed to run but would have been prevented if the Config CI policy were enforced. Added in Windows Server 2016 and Windows 10.
|
||||
8029, *<File name> * was prevented from running due to Config CI policy. Added in Windows Server 2016 and Windows 10.
|
||||
8030, ManagedInstaller check SUCCEEDED during Appid verification of * Added in Windows Server 2016 and Windows 10.
|
||||
8031, SmartlockerFilter detected file * being written by process * Added in Windows Server 2016 and Windows 10.
|
||||
8032, ManagedInstaller check FAILED during Appid verification of * Added in Windows Server 2016 and Windows 10.
|
||||
8033, ManagedInstaller check FAILED during Appid verification of * . Allowed to run due to Audit AppLocker Policy. Added in Windows Server 2016 and Windows 10.
|
||||
8034, ManagedInstaller Script check FAILED during Appid verification of * Added in Windows Server 2016 and Windows 10.
|
||||
8035, ManagedInstaller Script check SUCCEEDED during Appid verification of * Added in Windows Server 2016 and Windows 10.
|
||||
8036, * was prevented from running due to Config CI policy Added in Windows Server 2016 and Windows 10.
|
||||
8037, * passed Config CI policy and was allowed to run. Added in Windows Server 2016 and Windows 10.
|
||||
8038, Publisher info: Subject: * Issuer: * Signature index * (* total) Added in Windows Server 2016 and Windows 10.
|
||||
8039, Package family name * version * was allowed to install or update but would have been prevented if the Config CI policy Added in Windows Server 2016 and Windows 10.
|
||||
8040, Package family name * version * was prevented from installing or updating due to Config CI policy Added in Windows Server 2016 and Windows 10.
|
||||
|
-18
@@ -1,18 +0,0 @@
|
||||
ID,ASR_Rule
|
||||
56A863A9-875E-4185-98A7-B882C64B5CE5,Block abuse of exploited vulnerable signed drivers
|
||||
7674BA52-37EB-4A4F-A9A1-F0F9A1619A2C,Block Adobe Reader from creating child processes
|
||||
D4F940AB-401B-4EFC-AADC-AD5F3C50688A,Block all Office applications from creating child processes
|
||||
9E6C4E1F-7D60-472F-BA1A-A39EF669E4B2,Block credential stealing from the Windows local security authority subsystem (lsass.exe)
|
||||
BE9BA2D9-53EA-4CDC-84E5-9B1EEEE46550,Block executable content from email client and webmail
|
||||
01443614-CD74-433A-B99E-2ECDC07BFC25,Block executable files from running unless they meet a prevalence - age - or trusted list criterion
|
||||
5BEB7EFE-FD9A-4556-801D-275E5FFC04CC,Block execution of potentially obfuscated scripts
|
||||
D3E037E1-3EB8-44C8-A917-57927947596D,Block JavaScript or VBScript from launching downloaded executable content
|
||||
3B576869-A4EC-4529-8536-B80A7769E899,Block Office applications from creating executable content
|
||||
75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84,Block Office applications from injecting code into other processes
|
||||
26190899-1602-49E8-8B27-EB1D0A1CE869,Block Office communication application from creating child processes
|
||||
E6DB77E5-3DF2-4CF1-B95A-636979351E5B,Block persistence through WMI event subscription
|
||||
D1E49AAC-8F56-4280-B9BA-993A6D77406C,Block process creations originating from PSExec and WMI commands
|
||||
B2B3F03D-6A65-4F7B-A9C7-1C7EF74A9BA4,Block untrusted and unsigned processes that run from USB
|
||||
92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B,Block Win32 API calls from Office macros
|
||||
C1DB55AB-C21A-4637-BB3F-A12568109D35,Use advanced protection against ransomware
|
||||
A8F5898E-1DC8-49A9-9878-85004B8A61E6,Block Webshell creation for Servers
|
||||
|
@@ -1,31 +0,0 @@
|
||||
attacker_tool_names,description
|
||||
remcom.exe,This process is an open source replacement to psexec and is not typically seen in an enterprise environment.
|
||||
pwdump.exe,This process is associated with a tool used to dump password hashes on a Windows system.
|
||||
pwdump2.exe,This process is associated with a tool used to dump password hashes on a Windows system.
|
||||
nc.exe,This process is an open source tool used for network communications.
|
||||
wce.exe,This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks.
|
||||
cain.exe,This process is associated with a tool used to collect user credentials and execute attacks.
|
||||
nmap.exe,This process is an open source network mapping tool used to identify hosts and listening services on a network.
|
||||
kidlogger.exe,This process is associated with a tool used to collect keyboard input on a host.
|
||||
isass.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
|
||||
svch0st.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process.
|
||||
at.exe,This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility.
|
||||
getmail.exe,This process is seen to be used by attackers to extract email files from host machines.
|
||||
ntdll.exe,This process was identified as malicious by DHS Alert TA18-074A.
|
||||
netpass.exe,This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user.
|
||||
WebBrowserPassView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers.
|
||||
OutlookAddressBookView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook.
|
||||
mailpv.exe,This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients.
|
||||
NLBrute.exe,A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords.
|
||||
selfdel.exe,This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities.
|
||||
masscan.exe,This executable was delivered in the XMRig Crypto Miner
|
||||
Massscan_GUI.exe,This executable was delivered in the XMRig Crypto Miner
|
||||
KPortScan3.exe,This executable was delivered in the XMRig Crypto Miner and is commonly used by attackers to scan the internet
|
||||
NLAChecker.exe,A scanner tool that checks for Windows hosts for Network Level Authentication. This tool allows attackers to detect Windows Servers with RDP without NLA enabled which facilitates the use of brute force non microsoft rdp tools or exploits
|
||||
ns.exe,A commonly used tool used by attackers to scan and map file shares
|
||||
SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts.
|
||||
kportscan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks.
|
||||
advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
|
||||
mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets.
|
||||
certify.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
|
||||
certipy.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS)
|
||||
|
@@ -1 +0,0 @@
|
||||
identity
|
||||
|
@@ -1 +0,0 @@
|
||||
src_ip,numDataPoints,latestCount,avgBlockedConnections,stdevBlockedConnections
|
||||
|
@@ -1 +0,0 @@
|
||||
domain,domain_abuse
|
||||
|
@@ -1,47 +0,0 @@
|
||||
browser_process_name,browser_object_path,isAllowed
|
||||
"*Sputnik.exe","*Sputnik\Sputnik\User Data\Default\Login Data*", true
|
||||
"*ChromePlus.exe","*MapleStudio\ChromePlus\User Data\Default\Login Data*", true
|
||||
"*QIP Surf.exe","*QIP Surf\User Data\Default\Login Data*", true
|
||||
"*BlackHawk.exe","*BlackHawk\User Data\Default\Login Data*", true
|
||||
"*7Star.exe","*7Star\7Star\User Data\Default\Login Data*", true
|
||||
"*Sleipnir5.exe","*Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data*", true
|
||||
"*Citrio.exe","*CatalinaGroup\Citrio\User Data\Default\Login Data*", true
|
||||
"*Chrome SxS.exe","*Google\Chrome SxS\User Data\Default\Login Data*", true
|
||||
"*Chrome.exe","*Google\Chrome\User Data\Default\Login Data*", true
|
||||
"*Coowon.exe","*Coowon\Coowon\User Data\Default\Login Data*", true
|
||||
"*CocCocBrowser.exe","*CocCoc\Browser\User Data\Default\Login Data*", true
|
||||
"*Uran.exe","*uCozMedia\Uran\User Data\Default\Login Data*", true
|
||||
"*QQBrowser.exe","*Tencent\QQBrowser\User Data\Default\Login Data*", true
|
||||
"*Orbitum.exe","*Orbitum\User Data\Default\Login Data*", true
|
||||
"*Slimjet.exe","*Slimjet\User Data\Default\Login Data*", true
|
||||
"*Iridium.exe","*Iridium\User Data\Default\Login Data*", true
|
||||
"*Vivaldi.exe","*Vivaldi\User Data\Default\Login Data*", true
|
||||
"*Chromium.exe","*Chromium\User Data\Default\Login Data*", true
|
||||
"*GhostBrowser.exe","*GhostBrowser\User Data\Default\Login Data*", true
|
||||
"*CentBrowser.exe","*CentBrowser\User Data\Default\Login Data*", true
|
||||
"*Xvast.exe","*Xvast\User Data\Default\Login Data*", true
|
||||
"*Chedot.exe","*Chedot\User Data\Default\Login Data*", true
|
||||
"*SuperBird.exe","*SuperBird\User Data\Default\Login Data*", true
|
||||
"*360Browser.exe","*360Browser\Browser\User Data\Default\Login Data*", true
|
||||
"*360Chrome.exe","*360Chrome\Chrome\User Data\Default\Login Data*", true
|
||||
"*dragon.exe","*Comodo\Dragon\User Data\Default\Login Data*", true
|
||||
"*brave.exe","*BraveSoftware\Brave-Browser\User Data\Default\Login Data*", true
|
||||
"*brave.exe","*BraveSoftware\Brave-Browser\User Data\Local State*", true
|
||||
"*brave.exe","*BraveSoftware\Brave-Browser\User Data\Default*", true
|
||||
"*torch.exe","*Torch\User Data\Default\Login Data*", true
|
||||
"*UCBrowser.exe","*UCBrowser\User Data_i18n\Default\UC Login Data.18*", true
|
||||
"*BliskBrowser.exe","*Blisk\User Data\Default\Login Data*", true
|
||||
"*Epic Privacy Browser.exe","*Epic Privacy Browser\User Data\Default\Login Data*", true
|
||||
"*nichrome.exe","*Nichrome\User Data\Default\Login Data*", true
|
||||
"*AmigoBrowser.exe","*Amigo\User Data\Default\Login Data*", true
|
||||
"*KometaBrowser.exe","*Kometa\User Data\Default\Login Data*", true
|
||||
"*XpomBrowser.exe","*Xpom\User Data\Default\Login Data*", true
|
||||
"*msedge.exe","*Microsoft\Edge\User Data\Default\Login Data*", true
|
||||
"*LiebaoBrowser.exe","*Liebao7\User Data\Default\EncryptedStorage*", true
|
||||
"*AvastBrowser.exe","*AVAST Software\Browser\User Data\Default\Login Data*", true
|
||||
"*Kinza.exe","*Kinza\User Data\Default\Login Data*", true
|
||||
"*seamonkey.exe","*Mozilla\SeaMonkey\Profiles\logins.json*", true
|
||||
"*icedragon.exe","*Comodo\IceDragon\Profiles\logins.json*", true
|
||||
"*cyberfox.exe","*8pecxstudios\Cyberfox\Profiles\logins.json*", true
|
||||
"*SlimBrowser.exe","*FlashPeak\SlimBrowser\Profiles\logins.json*", true
|
||||
"*palemoon.exe","*Moonchild Productions\Pale Moon\Profiles\logins.json*", true
|
||||
|
@@ -1,259 +0,0 @@
|
||||
"_mkv_child","_timediff",ascii,base64bin,base64char,bin,dec,hex
|
||||
0,,":NUL:",000000,A,00000000,0,00
|
||||
1,,"",000001,B,00000001,1,01
|
||||
2,,"",000010,C,00000010,2,02
|
||||
3,,"",000011,D,00000011,3,03
|
||||
4,,"",000100,E,00000100,4,04
|
||||
5,,"",000101,F,00000101,5,05
|
||||
6,,"",000110,G,00000110,6,06
|
||||
7,,"",000111,H,00000111,7,07
|
||||
8,,"",001000,I,00001000,8,08
|
||||
9,," ",001001,J,00001001,9,09
|
||||
10,,"
|
||||
",001010,K,00001010,10,0A
|
||||
11,,"",001011,L,00001011,11,0B
|
||||
12,,"",001100,M,00001100,12,0C
|
||||
13,,"",001101,N,00001101,13,0D
|
||||
14,,"",001110,O,00001110,14,0E
|
||||
15,,"",001111,P,00001111,15,0F
|
||||
16,,"",010000,Q,00010000,16,10
|
||||
17,,"",010001,R,00010001,17,11
|
||||
18,,"",010010,S,00010010,18,12
|
||||
19,,"",010011,T,00010011,19,13
|
||||
20,,"",010100,U,00010100,20,14
|
||||
21,,"",010101,V,00010101,21,15
|
||||
22,,"",010110,W,00010110,22,16
|
||||
23,,"",010111,X,00010111,23,17
|
||||
24,,"",011000,Y,00011000,24,18
|
||||
25,,"",011001,Z,00011001,25,19
|
||||
26,,"",011010,a,00011010,26,1A
|
||||
27,,"",011011,b,00011011,27,1B
|
||||
28,,"",011100,c,00011100,28,1C
|
||||
29,,"",011101,d,00011101,29,1D
|
||||
30,,"",011110,e,00011110,30,1E
|
||||
31,,"",011111,f,00011111,31,1F
|
||||
32,,":SPACE:",100000,g,00100000,32,20
|
||||
33,,"!",100001,h,00100001,33,21
|
||||
34,,"""",100010,i,00100010,34,22
|
||||
35,,"#",100011,j,00100011,35,23
|
||||
36,,"$",100100,k,00100100,36,24
|
||||
37,,"%",100101,l,00100101,37,25
|
||||
38,,"&",100110,m,00100110,38,26
|
||||
39,,"'",100111,n,00100111,39,27
|
||||
40,,"(",101000,o,00101000,40,28
|
||||
41,,")",101001,p,00101001,41,29
|
||||
42,,"*",101010,q,00101010,42,2A
|
||||
43,,"+",101011,r,00101011,43,2B
|
||||
44,,",",101100,s,00101100,44,2C
|
||||
45,,"-",101101,t,00101101,45,2D
|
||||
46,,".",101110,u,00101110,46,2E
|
||||
47,,"/",101111,v,00101111,47,2F
|
||||
48,,0,110000,w,00110000,48,30
|
||||
49,,1,110001,x,00110001,49,31
|
||||
50,,2,110010,y,00110010,50,32
|
||||
51,,3,110011,z,00110011,51,33
|
||||
52,,4,110100,0,00110100,52,34
|
||||
53,,5,110101,1,00110101,53,35
|
||||
54,,6,110110,2,00110110,54,36
|
||||
55,,7,110111,3,00110111,55,37
|
||||
56,,8,111000,4,00111000,56,38
|
||||
57,,9,111001,5,00111001,57,39
|
||||
58,,":",111010,6,00111010,58,3A
|
||||
59,,";",111011,7,00111011,59,3B
|
||||
60,,"<",111100,8,00111100,60,3C
|
||||
61,,"=",111101,9,00111101,61,3D
|
||||
62,,">",111110,"+",00111110,62,3E
|
||||
63,,"?",111111,"/",00111111,63,3F
|
||||
64,,"@",,,01000000,64,40
|
||||
65,,A,,,01000001,65,41
|
||||
66,,B,,,01000010,66,42
|
||||
67,,C,,,01000011,67,43
|
||||
68,,D,,,01000100,68,44
|
||||
69,,E,,,01000101,69,45
|
||||
70,,F,,,01000110,70,46
|
||||
71,,G,,,01000111,71,47
|
||||
72,,H,,,01001000,72,48
|
||||
73,,I,,,01001001,73,49
|
||||
74,,J,,,01001010,74,4A
|
||||
75,,K,,,01001011,75,4B
|
||||
76,,L,,,01001100,76,4C
|
||||
77,,M,,,01001101,77,4D
|
||||
78,,N,,,01001110,78,4E
|
||||
79,,O,,,01001111,79,4F
|
||||
80,,P,,,01010000,80,50
|
||||
81,,Q,,,01010001,81,51
|
||||
82,,R,,,01010010,82,52
|
||||
83,,S,,,01010011,83,53
|
||||
84,,T,,,01010100,84,54
|
||||
85,,U,,,01010101,85,55
|
||||
86,,V,,,01010110,86,56
|
||||
87,,W,,,01010111,87,57
|
||||
88,,X,,,01011000,88,58
|
||||
89,,Y,,,01011001,89,59
|
||||
90,,Z,,,01011010,90,5A
|
||||
91,,"[",,,01011011,91,5B
|
||||
92,,"\",,,01011100,92,5C
|
||||
93,,"]",,,01011101,93,5D
|
||||
94,,"^",,,01011110,94,5E
|
||||
95,,"_",,,01011111,95,5F
|
||||
96,,"`",,,01100000,96,60
|
||||
97,,a,,,01100001,97,61
|
||||
98,,b,,,01100010,98,62
|
||||
99,,c,,,01100011,99,63
|
||||
100,,d,,,01100100,100,64
|
||||
101,,e,,,01100101,101,65
|
||||
102,,f,,,01100110,102,66
|
||||
103,,g,,,01100111,103,67
|
||||
104,,h,,,01101000,104,68
|
||||
105,,i,,,01101001,105,69
|
||||
106,,j,,,01101010,106,6A
|
||||
107,,k,,,01101011,107,6B
|
||||
108,,l,,,01101100,108,6C
|
||||
109,,m,,,01101101,109,6D
|
||||
110,,n,,,01101110,110,6E
|
||||
111,,o,,,01101111,111,6F
|
||||
112,,p,,,01110000,112,70
|
||||
113,,q,,,01110001,113,71
|
||||
114,,r,,,01110010,114,72
|
||||
115,,s,,,01110011,115,73
|
||||
116,,t,,,01110100,116,74
|
||||
117,,u,,,01110101,117,75
|
||||
118,,v,,,01110110,118,76
|
||||
119,,w,,,01110111,119,77
|
||||
120,,x,,,01111000,120,78
|
||||
121,,y,,,01111001,121,79
|
||||
122,,z,,,01111010,122,7A
|
||||
123,,"{",,,01111011,123,7B
|
||||
124,,"|",,,01111100,124,7C
|
||||
125,,"}",,,01111101,125,7D
|
||||
126,,"~",,,01111110,126,7E
|
||||
127,,"",,,01111111,127,7F
|
||||
128,,"",,,10000000,128,80
|
||||
129,,"",,,10000001,129,81
|
||||
130,,"",,,10000010,130,82
|
||||
131,,"",,,10000011,131,83
|
||||
132,,"",,,10000100,132,84
|
||||
133,,"
",,,10000101,133,85
|
||||
134,,"",,,10000110,134,86
|
||||
135,,"",,,10000111,135,87
|
||||
136,,"",,,10001000,136,88
|
||||
137,,"",,,10001001,137,89
|
||||
138,,"",,,10001010,138,8A
|
||||
139,,"",,,10001011,139,8B
|
||||
140,,"",,,10001100,140,8C
|
||||
141,,"",,,10001101,141,8D
|
||||
142,,"",,,10001110,142,8E
|
||||
143,,"",,,10001111,143,8F
|
||||
144,,"",,,10010000,144,90
|
||||
145,,"",,,10010001,145,91
|
||||
146,,"",,,10010010,146,92
|
||||
147,,"",,,10010011,147,93
|
||||
148,,"",,,10010100,148,94
|
||||
149,,"",,,10010101,149,95
|
||||
150,,"",,,10010110,150,96
|
||||
151,,"",,,10010111,151,97
|
||||
152,,"",,,10011000,152,98
|
||||
153,,"",,,10011001,153,99
|
||||
154,,"",,,10011010,154,9A
|
||||
155,,"",,,10011011,155,9B
|
||||
156,,"",,,10011100,156,9C
|
||||
157,,"",,,10011101,157,9D
|
||||
158,,"",,,10011110,158,9E
|
||||
159,,"",,,10011111,159,9F
|
||||
160,," ",,,10100000,160,A0
|
||||
161,,"¡",,,10100001,161,A1
|
||||
162,,"¢",,,10100010,162,A2
|
||||
163,,"£",,,10100011,163,A3
|
||||
164,,"¤",,,10100100,164,A4
|
||||
165,,"¥",,,10100101,165,A5
|
||||
166,,"¦",,,10100110,166,A6
|
||||
167,,"§",,,10100111,167,A7
|
||||
168,,"¨",,,10101000,168,A8
|
||||
169,,"©",,,10101001,169,A9
|
||||
170,,"ª",,,10101010,170,AA
|
||||
171,,"«",,,10101011,171,AB
|
||||
172,,"¬",,,10101100,172,AC
|
||||
173,,"",,,10101101,173,AD
|
||||
174,,"®",,,10101110,174,AE
|
||||
175,,"¯",,,10101111,175,AF
|
||||
176,,"°",,,10110000,176,B0
|
||||
177,,"±",,,10110001,177,B1
|
||||
178,,"²",,,10110010,178,B2
|
||||
179,,"³",,,10110011,179,B3
|
||||
180,,"´",,,10110100,180,B4
|
||||
181,,"µ",,,10110101,181,B5
|
||||
182,,"¶",,,10110110,182,B6
|
||||
183,,"·",,,10110111,183,B7
|
||||
184,,"¸",,,10111000,184,B8
|
||||
185,,"¹",,,10111001,185,B9
|
||||
186,,"º",,,10111010,186,BA
|
||||
187,,"»",,,10111011,187,BB
|
||||
188,,"¼",,,10111100,188,BC
|
||||
189,,"½",,,10111101,189,BD
|
||||
190,,"¾",,,10111110,190,BE
|
||||
191,,"¿",,,10111111,191,BF
|
||||
192,,"À",,,11000000,192,C0
|
||||
193,,"Á",,,11000001,193,C1
|
||||
194,,"Â",,,11000010,194,C2
|
||||
195,,"Ã",,,11000011,195,C3
|
||||
196,,"Ä",,,11000100,196,C4
|
||||
197,,"Å",,,11000101,197,C5
|
||||
198,,"Æ",,,11000110,198,C6
|
||||
199,,"Ç",,,11000111,199,C7
|
||||
200,,"È",,,11001000,200,C8
|
||||
201,,"É",,,11001001,201,C9
|
||||
202,,"Ê",,,11001010,202,CA
|
||||
203,,"Ë",,,11001011,203,CB
|
||||
204,,"Ì",,,11001100,204,CC
|
||||
205,,"Í",,,11001101,205,CD
|
||||
206,,"Î",,,11001110,206,CE
|
||||
207,,"Ï",,,11001111,207,CF
|
||||
208,,"Ð",,,11010000,208,D0
|
||||
209,,"Ñ",,,11010001,209,D1
|
||||
210,,"Ò",,,11010010,210,D2
|
||||
211,,"Ó",,,11010011,211,D3
|
||||
212,,"Ô",,,11010100,212,D4
|
||||
213,,"Õ",,,11010101,213,D5
|
||||
214,,"Ö",,,11010110,214,D6
|
||||
215,,"×",,,11010111,215,D7
|
||||
216,,"Ø",,,11011000,216,D8
|
||||
217,,"Ù",,,11011001,217,D9
|
||||
218,,"Ú",,,11011010,218,DA
|
||||
219,,"Û",,,11011011,219,DB
|
||||
220,,"Ü",,,11011100,220,DC
|
||||
221,,"Ý",,,11011101,221,DD
|
||||
222,,"Þ",,,11011110,222,DE
|
||||
223,,"ß",,,11011111,223,DF
|
||||
224,,"à",,,11100000,224,E0
|
||||
225,,"á",,,11100001,225,E1
|
||||
226,,"â",,,11100010,226,E2
|
||||
227,,"ã",,,11100011,227,E3
|
||||
228,,"ä",,,11100100,228,E4
|
||||
229,,"å",,,11100101,229,E5
|
||||
230,,"æ",,,11100110,230,E6
|
||||
231,,"ç",,,11100111,231,E7
|
||||
232,,"è",,,11101000,232,E8
|
||||
233,,"é",,,11101001,233,E9
|
||||
234,,"ê",,,11101010,234,EA
|
||||
235,,"ë",,,11101011,235,EB
|
||||
236,,"ì",,,11101100,236,EC
|
||||
237,,"í",,,11101101,237,ED
|
||||
238,,"î",,,11101110,238,EE
|
||||
239,,"ï",,,11101111,239,EF
|
||||
240,,"ð",,,11110000,240,F0
|
||||
241,,"ñ",,,11110001,241,F1
|
||||
242,,"ò",,,11110010,242,F2
|
||||
243,,"ó",,,11110011,243,F3
|
||||
244,,"ô",,,11110100,244,F4
|
||||
245,,"õ",,,11110101,245,F5
|
||||
246,,"ö",,,11110110,246,F6
|
||||
247,,"÷",,,11110111,247,F7
|
||||
248,,"ø",,,11111000,248,F8
|
||||
249,,"ù",,,11111001,249,F9
|
||||
250,,"ú",,,11111010,250,FA
|
||||
251,,"û",,,11111011,251,FB
|
||||
252,,"ü",,,11111100,252,FC
|
||||
253,,"ý",,,11111101,253,FD
|
||||
254,,"þ",,,11111110,254,FE
|
||||
255,,"ÿ",,,11111111,255,FF
|
||||
,,,000000,"=",,,
|
||||
|
@@ -1 +0,0 @@
|
||||
count,domain,type,query,answer
|
||||
|
@@ -1,2 +0,0 @@
|
||||
username
|
||||
Administrator
|
||||
|
@@ -1 +0,0 @@
|
||||
domain,isValidDomain
|
||||
|
File diff suppressed because it is too large
Load Diff
@@ -1 +0,0 @@
|
||||
dynamic_dns_domains, isDynDNS_local
|
||||
|
-403
@@ -1,403 +0,0 @@
|
||||
library,islibrary
|
||||
outllib.dll,TRUE
|
||||
iviewers.dll,TRUE
|
||||
hha.dll,TRUE
|
||||
aclui.dll,TRUE
|
||||
xwtpw32.dll,TRUE
|
||||
xwizards.dll,TRUE
|
||||
xpsservices.dll,TRUE
|
||||
xolehlp.dll,TRUE
|
||||
xmllite.dll,TRUE
|
||||
wwapi.dll,TRUE
|
||||
wwancfg.dll,TRUE
|
||||
wtsapi32.dll,TRUE
|
||||
wsmsvc.dll,TRUE
|
||||
wshelper.dll,TRUE
|
||||
wshbth.dll,TRUE
|
||||
wscapi.dll,TRUE
|
||||
wpdshext.dll,TRUE
|
||||
wofutil.dll,TRUE
|
||||
wmsgapi.dll,TRUE
|
||||
wmpdui.dll,TRUE
|
||||
wmiutils.dll,TRUE
|
||||
wmidcom.dll,TRUE
|
||||
wmiclnt.dll,TRUE
|
||||
wlidprov.dll,TRUE
|
||||
wldp.dll,TRUE
|
||||
wlbsctrl.dll,TRUE
|
||||
wlancfg.dll,TRUE
|
||||
wlanapi.dll,TRUE
|
||||
wkscli.dll,TRUE
|
||||
winsync.dll,TRUE
|
||||
winsta.dll,TRUE
|
||||
winsqlite3.dll,TRUE
|
||||
winscard.dll,TRUE
|
||||
winrnr.dll,TRUE
|
||||
winnsi.dll,TRUE
|
||||
winmm.dll,TRUE
|
||||
winmde.dll,TRUE
|
||||
winipsec.dll,TRUE
|
||||
wininet.dll,TRUE
|
||||
winhttp.dll,TRUE
|
||||
windowsudk.shellcommon.dll,TRUE
|
||||
windowsperformancerecordercontrol.dll,TRUE
|
||||
windowscodecsext.dll,TRUE
|
||||
windowscodecs.dll,TRUE
|
||||
windows.ui.immersive.dll,TRUE
|
||||
windows.storage.search.dll,TRUE
|
||||
windows.storage.dll,TRUE
|
||||
winbrand.dll,TRUE
|
||||
winbio.dll,TRUE
|
||||
wimgapi.dll,TRUE
|
||||
whhelper.dll,TRUE
|
||||
wevtapi.dll,TRUE
|
||||
wer.dll,TRUE
|
||||
wecapi.dll,TRUE
|
||||
webservices.dll,TRUE
|
||||
wdscore.dll,TRUE
|
||||
wdi.dll,TRUE
|
||||
wcnnetsh.dll,TRUE
|
||||
wcmapi.dll,TRUE
|
||||
wbemsvc.dll,TRUE
|
||||
wbemprox.dll,TRUE
|
||||
vsstrace.dll,TRUE
|
||||
vssapi.dll,TRUE
|
||||
virtdisk.dll,TRUE
|
||||
version.dll,TRUE
|
||||
vdsutil.dll,TRUE
|
||||
vaultcli.dll,TRUE
|
||||
uxtheme.dll,TRUE
|
||||
uxinit.dll,TRUE
|
||||
utildll.dll,TRUE
|
||||
userenv.dll,TRUE
|
||||
urlmon.dll,TRUE
|
||||
upshared.dll,TRUE
|
||||
updatepolicy.dll,TRUE
|
||||
unattend.dll,TRUE
|
||||
umpdc.dll,TRUE
|
||||
uiribbon.dll,TRUE
|
||||
uireng.dll,TRUE
|
||||
uiautomationcore.dll,TRUE
|
||||
uianimation.dll,TRUE
|
||||
twinui.appcore.dll,TRUE
|
||||
twinapi.dll,TRUE
|
||||
twext.dll,TRUE
|
||||
ttdrecord.dll,TRUE
|
||||
tsworkspace.dll,TRUE
|
||||
tquery.dll,TRUE
|
||||
tpmcoreprovisioning.dll,TRUE
|
||||
timesync.dll,TRUE
|
||||
tdh.dll,TRUE
|
||||
tbs.dll,TRUE
|
||||
tapi32.dll,TRUE
|
||||
systemsettingsthresholdadminflowui.dll,TRUE
|
||||
sxshared.dll,TRUE
|
||||
structuredquery.dll,TRUE
|
||||
staterepository.core.dll,TRUE
|
||||
ssshim.dll,TRUE
|
||||
sspicli.dll,TRUE
|
||||
ssp_isv.exe_rsaenh.dll,TRUE
|
||||
ssp.exe_rsaenh.dll,TRUE
|
||||
srvcli.dll,TRUE
|
||||
srpapi.dll,TRUE
|
||||
srmtrace.dll,TRUE
|
||||
srcore.dll,TRUE
|
||||
srclient.dll,TRUE
|
||||
sppcext.dll,TRUE
|
||||
sppc.dll,TRUE
|
||||
spp.dll,TRUE
|
||||
spectrumsyncclient.dll,TRUE
|
||||
snmpapi.dll,TRUE
|
||||
slc.dll,TRUE
|
||||
shell32.dll,TRUE
|
||||
security.dll,TRUE
|
||||
secur32.dll,TRUE
|
||||
schedcli.dll,TRUE
|
||||
scecli.dll,TRUE
|
||||
scansetting.dll,TRUE
|
||||
sas.dll,TRUE
|
||||
sapi_onecore.dll,TRUE
|
||||
samlib.dll,TRUE
|
||||
samcli.dll,TRUE
|
||||
rtworkq.dll,TRUE
|
||||
rtutils.dll,TRUE
|
||||
rsaenh.dll,TRUE
|
||||
rpcnsh.dll,TRUE
|
||||
rmclient.dll,TRUE
|
||||
resutils.dll,TRUE
|
||||
resetengine.dll,TRUE
|
||||
reseteng.dll,TRUE
|
||||
regapi.dll,TRUE
|
||||
reagent.dll,TRUE
|
||||
rasmontr.dll,TRUE
|
||||
rasman.dll,TRUE
|
||||
rasgcw.dll,TRUE
|
||||
rasdlg.dll,TRUE
|
||||
rasapi32.dll,TRUE
|
||||
radcui.dll,TRUE
|
||||
puiapi.dll,TRUE
|
||||
prvdmofcomp.dll,TRUE
|
||||
proximityservicepal.dll,TRUE
|
||||
proximitycommon.dll,TRUE
|
||||
propsys.dll,TRUE
|
||||
profapi.dll,TRUE
|
||||
prntvpt.dll,TRUE
|
||||
printui.dll,TRUE
|
||||
powrprof.dll,TRUE
|
||||
polstore.dll,TRUE
|
||||
policymanager.dll,TRUE
|
||||
pnrpnsp.dll,TRUE
|
||||
playsndsrv.dll,TRUE
|
||||
pla.dll,TRUE
|
||||
pkeyhelper.dll,TRUE
|
||||
peerdistsh.dll,TRUE
|
||||
pdh.dll,TRUE
|
||||
pcaui.dll,TRUE
|
||||
p9np.dll,TRUE
|
||||
p2pnetsh.dll,TRUE
|
||||
p2p.dll,TRUE
|
||||
osuninst.dll,TRUE
|
||||
osksupport.dll,TRUE
|
||||
osbaseln.dll,TRUE
|
||||
opcservices.dll,TRUE
|
||||
onex.dll,TRUE
|
||||
omadmapi.dll,TRUE
|
||||
oleacc.dll,TRUE
|
||||
oci.dll,TRUE
|
||||
ntshrui.dll,TRUE
|
||||
ntmarta.dll,TRUE
|
||||
ntlmshared.dll,TRUE
|
||||
ntlanman.dll,TRUE
|
||||
ntdsapi.dll,TRUE
|
||||
nshwfp.dll,TRUE
|
||||
nshipsec.dll,TRUE
|
||||
nshhttp.dll,TRUE
|
||||
npmproxy.dll,TRUE
|
||||
nlansp_c.dll,TRUE
|
||||
nlaapi.dll,TRUE
|
||||
ninput.dll,TRUE
|
||||
newdev.dll,TRUE
|
||||
networkexplorer.dll,TRUE
|
||||
netutils.dll,TRUE
|
||||
nettrace.dll,TRUE
|
||||
netshell.dll,TRUE
|
||||
netsetupapi.dll,TRUE
|
||||
netprovfw.dll,TRUE
|
||||
netprofm.dll,TRUE
|
||||
netplwiz.dll,TRUE
|
||||
netjoin.dll,TRUE
|
||||
netiohlp.dll,TRUE
|
||||
netid.dll,TRUE
|
||||
netapi32.dll,TRUE
|
||||
ndfapi.dll,TRUE
|
||||
ncrypt.dll,TRUE
|
||||
napinsp.dll,TRUE
|
||||
mtxclu.dll,TRUE
|
||||
msxml3.dll,TRUE
|
||||
mswsock.dll,TRUE
|
||||
mswb7.dll,TRUE
|
||||
msvcp110_win.dll,TRUE
|
||||
msutb.dll,TRUE
|
||||
mstracer.dll,TRUE
|
||||
msiso.dll,TRUE
|
||||
msi.dll,TRUE
|
||||
msftedit.dll,TRUE
|
||||
msdtctm.dll,TRUE
|
||||
msdrm.dll,TRUE
|
||||
msctfmonitor.dll,TRUE
|
||||
msctf.dll,TRUE
|
||||
mscoree.dll,TRUE
|
||||
mscms.dll,TRUE
|
||||
msacm32.dll,TRUE
|
||||
mrmcorer.dll,TRUE
|
||||
mpsvc.dll,TRUE
|
||||
mprapi.dll,TRUE
|
||||
mpr.dll,TRUE
|
||||
mpclient.dll,TRUE
|
||||
mobilenetworking.dll,TRUE
|
||||
mmdevapi.dll,TRUE
|
||||
mlang.dll,TRUE
|
||||
miutils.dll,TRUE
|
||||
mintdh.dll,TRUE
|
||||
midimap.dll,TRUE
|
||||
mi.dll,TRUE
|
||||
mfplat.dll,TRUE
|
||||
mfcore.dll,TRUE
|
||||
mfc42u.dll,TRUE
|
||||
mdmdiagnostics.dll,TRUE
|
||||
mbaexmlparser.dll,TRUE
|
||||
mapistub.dll,TRUE
|
||||
maintenanceui.dll,TRUE
|
||||
magnification.dll,TRUE
|
||||
lrwizdll.dll,TRUE
|
||||
lpksetupproxyserv.dll,TRUE
|
||||
logoncontroller.dll,TRUE
|
||||
logoncli.dll,TRUE
|
||||
lockhostingframework.dll,TRUE
|
||||
loadperf.dll,TRUE
|
||||
linkinfo.dll,TRUE
|
||||
licensingdiagspp.dll,TRUE
|
||||
licensemanagerapi.dll,TRUE
|
||||
ktmw32.dll,TRUE
|
||||
ksuser.dll,TRUE
|
||||
kdstub.dll,TRUE
|
||||
joinutil.dll,TRUE
|
||||
iumsdk.dll,TRUE
|
||||
iumbase.dll,TRUE
|
||||
isv.exe_rsaenh.dll,TRUE
|
||||
iscsium.dll,TRUE
|
||||
iscsidsc.dll,TRUE
|
||||
iri.dll,TRUE
|
||||
iphlpapi.dll,TRUE
|
||||
inproclogger.dll,TRUE
|
||||
ifsutil.dll,TRUE
|
||||
ifmon.dll,TRUE
|
||||
iertutil.dll,TRUE
|
||||
iedkcs32.dll,TRUE
|
||||
ieadvpack.dll,TRUE
|
||||
idstore.dll,TRUE
|
||||
icmp.dll,TRUE
|
||||
httpapi.dll,TRUE
|
||||
hnetmon.dll,TRUE
|
||||
hid.dll,TRUE
|
||||
gpapi.dll,TRUE
|
||||
getuname.dll,TRUE
|
||||
fxstiff.dll,TRUE
|
||||
fxsst.dll,TRUE
|
||||
fxsapi.dll,TRUE
|
||||
fwpuclnt.dll,TRUE
|
||||
fwpolicyiomgr.dll,TRUE
|
||||
fwcfg.dll,TRUE
|
||||
fwbase.dll,TRUE
|
||||
fvewiz.dll,TRUE
|
||||
fveskybackup.dll,TRUE
|
||||
fveapi.dll,TRUE
|
||||
framedynos.dll,TRUE
|
||||
fltlib.dll,TRUE
|
||||
flightsettings.dll,TRUE
|
||||
firewallapi.dll,TRUE
|
||||
fhsvcctl.dll,TRUE
|
||||
fhcfg.dll,TRUE
|
||||
feclient.dll,TRUE
|
||||
fddevquery.dll,TRUE
|
||||
faultrep.dll,TRUE
|
||||
fastprox.dll,TRUE
|
||||
explorerframe.dll,TRUE
|
||||
execmodelproxy.dll,TRUE
|
||||
esent.dll,TRUE
|
||||
efsutil.dll,TRUE
|
||||
efsadu.dll,TRUE
|
||||
edputil.dll,TRUE
|
||||
edgeiso.dll,TRUE
|
||||
eappprxy.dll,TRUE
|
||||
eappcfg.dll,TRUE
|
||||
dynamoapi.dll,TRUE
|
||||
dxva2.dll,TRUE
|
||||
dxgi.dll,TRUE
|
||||
dxcore.dll,TRUE
|
||||
dwrite.dll,TRUE
|
||||
dwmcore.dll,TRUE
|
||||
dwmapi.dll,TRUE
|
||||
dusmapi.dll,TRUE
|
||||
duser.dll,TRUE
|
||||
dui70.dll,TRUE
|
||||
dsrole.dll,TRUE
|
||||
dsreg.dll,TRUE
|
||||
dsprop.dll,TRUE
|
||||
dsparse.dll,TRUE
|
||||
dsclient.dll,TRUE
|
||||
drvstore.dll,TRUE
|
||||
drprov.dll,TRUE
|
||||
dpx.dll,TRUE
|
||||
dot3cfg.dll,TRUE
|
||||
dot3api.dll,TRUE
|
||||
dnsapi.dll,TRUE
|
||||
dmxmlhelputils.dll,TRUE
|
||||
dmpushproxy.dll,TRUE
|
||||
dmprocessxmlfiltered.dll,TRUE
|
||||
dmoleaututils.dll,TRUE
|
||||
dmiso8601utils.dll,TRUE
|
||||
dmenterprisediagnostics.dll,TRUE
|
||||
dmenrollengine.dll,TRUE
|
||||
dmcommandlineutils.dll,TRUE
|
||||
dmcmnutils.dll,TRUE
|
||||
dmcfgutils.dll,TRUE
|
||||
dismcore.dll,TRUE
|
||||
dismapi.dll,TRUE
|
||||
directmanipulation.dll,TRUE
|
||||
dhcpcsvc6.dll,TRUE
|
||||
dhcpcsvc.dll,TRUE
|
||||
dhcpcmonitor.dll,TRUE
|
||||
devrtl.dll,TRUE
|
||||
devobj.dll,TRUE
|
||||
devicepairing.dll,TRUE
|
||||
devicecredential.dll,TRUE
|
||||
deviceassociation.dll,TRUE
|
||||
desktopshellext.dll,TRUE
|
||||
defragproxy.dll,TRUE
|
||||
dcomp.dll,TRUE
|
||||
dcntel.dll,TRUE
|
||||
dbghelp.dll,TRUE
|
||||
dbgcore.dll,TRUE
|
||||
davclnt.dll,TRUE
|
||||
dataexchange.dll,TRUE
|
||||
d3dcompiler_47.dll,TRUE
|
||||
d3d9.dll,TRUE
|
||||
d3d12.dll,TRUE
|
||||
d3d11.dll,TRUE
|
||||
d3d10warp.dll,TRUE
|
||||
d3d10core.dll,TRUE
|
||||
d3d10_1core.dll,TRUE
|
||||
d3d10_1.dll,TRUE
|
||||
d3d10.dll,TRUE
|
||||
d2d1.dll,TRUE
|
||||
cscui.dll,TRUE
|
||||
cscobj.dll,TRUE
|
||||
cscapi.dll,TRUE
|
||||
cryptxml.dll,TRUE
|
||||
cryptui.dll,TRUE
|
||||
cryptsp.dll,TRUE
|
||||
cryptdll.dll,TRUE
|
||||
cryptbase.dll,TRUE
|
||||
credui.dll,TRUE
|
||||
coreuicomponents.dll,TRUE
|
||||
coremessaging.dll,TRUE
|
||||
coredplus.dll,TRUE
|
||||
connect.dll,TRUE
|
||||
configmanager2.dll,TRUE
|
||||
comdlg32.dll,TRUE
|
||||
colorui.dll,TRUE
|
||||
coloradapterclient.dll,TRUE
|
||||
cmutil.dll,TRUE
|
||||
cmpbk32.dll,TRUE
|
||||
clusapi.dll,TRUE
|
||||
clipc.dll,TRUE
|
||||
cldapi.dll,TRUE
|
||||
certenroll.dll,TRUE
|
||||
certcli.dll,TRUE
|
||||
cabview.dll,TRUE
|
||||
cabinet.dll,TRUE
|
||||
bootux.dll,TRUE
|
||||
bootmenuux.dll,TRUE
|
||||
bderepair.dll,TRUE
|
||||
bcrypt.dll,TRUE
|
||||
bcp47mrm.dll,TRUE
|
||||
bcp47langs.dll,TRUE
|
||||
bcd.dll,TRUE
|
||||
batmeter.dll,TRUE
|
||||
avrt.dll,TRUE
|
||||
authz.dll,TRUE
|
||||
authfwcfg.dll,TRUE
|
||||
auditpolcore.dll,TRUE
|
||||
audioses.dll,TRUE
|
||||
atl.dll,TRUE
|
||||
archiveint.dll,TRUE
|
||||
appxdeploymentclient.dll,TRUE
|
||||
appxalluserstore.dll,TRUE
|
||||
appvpolicy.dll,TRUE
|
||||
applicationframe.dll,TRUE
|
||||
apphelp.dll,TRUE
|
||||
aepic.dll,TRUE
|
||||
adsldpc.dll,TRUE
|
||||
activeds.dll,TRUE
|
||||
amsi.dll,TRUE
|
||||
|
@@ -1,886 +0,0 @@
|
||||
islibrary,library,excludes,ttp,comment
|
||||
TRUE,aclui.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
|
||||
TRUE,aclui.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
|
||||
TRUE,acrodistdll.dll,*\Program Files\Adobe\Acrobat *,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
|
||||
TRUE,acrodistdll.dll,*\Acrobat\acrodistdll*,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
|
||||
TRUE,activeds.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,activeds.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,adsldpc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,adsldpc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,aepic.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,aepic.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,apphelp.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,apphelp.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,applicationframe.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,applicationframe.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,appvpolicy.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,appwiz.cpl,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
|
||||
TRUE,appwiz.cpl,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
|
||||
TRUE,appxalluserstore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,appxalluserstore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,appxdeploymentclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,appxdeploymentclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,archiveint.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,archiveint.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ashldres.dll,*\Program Files\McAfee.com\VSO*,T1574.002,https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf
|
||||
TRUE,atl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,atl.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,atltracetoolui.dll,*\Program Files\Microsoft Visual Studio 11.0\Common7\Tools*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,audioses.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,audioses.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,auditpolcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,auditpolcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,authfwcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,authfwcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,authz.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,authz.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,avrt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,avrt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,basicnetutils.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
|
||||
TRUE,basicnetutils.dll,*\Program Files\BAIDU\BAIDUPINYIN\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
|
||||
TRUE,batmeter.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,batmeter.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,bcd.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bcd.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bcp47langs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bcp47langs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bcp47mrm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bcp47mrm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bcrypt.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,bcrypt.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,bderepair.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bootmenuux.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,bootux.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,cabinet.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cabinet.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cabview.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,cabview.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,certcli.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,certcli.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,certenroll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,certenroll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cfgmgr32.dll,*\Windows\System32\*,T1574.002,
|
||||
TRUE,cfgmgr32.dll,*\Windows\SysWOW64\*,T1574.002,
|
||||
TRUE,chrome_frame_helper.dll,*\Appdata\local\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
|
||||
TRUE,chrome_frame_helper.dll,*\Program Files\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
|
||||
TRUE,ciscosparklauncher.dll,*\Appdata\local\CiscoSparkLauncher*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
|
||||
TRUE,ciscosparklauncher.dll,*\AppData\Local\Programs\Cisco Spark\*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
|
||||
TRUE,classicexplorer32.dll,*\Program Files\Classic Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
|
||||
TRUE,classicexplorer32.dll,*\Program Files\Open-Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
|
||||
TRUE,cldapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cldapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,clipc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,clipc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,clusapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,clusapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cmpbk32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cmpbk32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cmutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,cmutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,coloradapterclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,coloradapterclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,colorui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,colorui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,comdlg32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,comdlg32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,commfunc.dll,*\Program Files\Lenovo\Communications Utility*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
|
||||
TRUE,configmanager2.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,connect.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,connect.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,coredplus.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,coremessaging.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,coremessaging.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,coreuicomponents.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,coreuicomponents.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,credui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,credui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptbase.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptdll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptdll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptsp.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,cryptsp.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,cryptui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptxml.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cryptxml.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cscapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cscapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,cscobj.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,cscobj.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,cscui.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,cscui.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,d2d1.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d2d1.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10_1.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10_1.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10_1core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10_1core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10warp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d10warp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d11.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d11.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d12.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d12.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d9.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3d9.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\redist\d3d\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\redist\d3d\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\wireshark*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\microsoft\edge\application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Program Files\Google\Chrome\Application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Appdata\local\microsoft\teams\stage*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dcompiler_47.dll,*\Microsoft\Teams\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,d3dx9_43.dll,*\Windows\System32\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
|
||||
TRUE,d3dx9_43.dll,*\Windows\SysWOW64\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
|
||||
TRUE,dataexchange.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,dataexchange.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,davclnt.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,davclnt.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
|
||||
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
|
||||
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
|
||||
TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbghelp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dbgmodel.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,dbgmodel.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,dbgmodel.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,dcntel.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dcomp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dcomp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,defragproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,defragproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,desktopshellext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,desktopshellext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,deviceassociation.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,deviceassociation.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,devicecredential.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,devicecredential.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,devicepairing.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,devicepairing.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,devobj.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,devobj.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,devrtl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,devrtl.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dhcpcmonitor.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dhcpcmonitor.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dhcpcsvc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dhcpcsvc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dhcpcsvc6.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dhcpcsvc6.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,directmanipulation.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,directmanipulation.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,dismapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dismapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dismcore.dll,*\Windows\System32\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
|
||||
TRUE,dismcore.dll,*\Windows\SysWOW64\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
|
||||
TRUE,dmcfgutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmcfgutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmcmnutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmcmnutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmcommandlineutils.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dmcommandlineutils.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dmenrollengine.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmenrollengine.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmenterprisediagnostics.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmiso8601utils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmiso8601utils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmoleaututils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmoleaututils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmprocessxmlfiltered.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmprocessxmlfiltered.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmpushproxy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmpushproxy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmxmlhelputils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dmxmlhelputils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dnsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dnsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dot3api.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dot3api.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dot3cfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dot3cfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dpx.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dpx.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,drprov.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,drprov.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,drvstore.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,drvstore.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dsclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsparse.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsparse.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsprop.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dsprop.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dsreg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsreg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsrole.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dsrole.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dui70.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dui70.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,duser.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,duser.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dusmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dusmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dwmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dwmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dwmcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dwrite.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dwrite.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dxcore.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dxcore.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,dxgi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dxgi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dxva2.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dxva2.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,dynamoapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,eappcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,eappcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,eappprxy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,eappprxy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,edgeiso.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,edgeiso.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,edputil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,edputil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,efsadu.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,efsadu.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,efsutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,efsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,esent.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,esent.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,execmodelproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,execmodelproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,explorerframe.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,explorerframe.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,facesdk.dll,*\Program Files\luxand\facesdk\bin\win64*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,fastprox.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,fastprox.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,faultrep.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,faultrep.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fddevquery.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,fddevquery.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,feclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,feclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fhcfg.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,fhcfg.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,fhsvcctl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,firewallapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,firewallapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,flightsettings.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,flightsettings.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,fltlib.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fltlib.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,formdll.dll,*\Program Files\Common Files\Microsoft Shared\NoteSync Forms*,T1574.002,https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1
|
||||
TRUE,framedynos.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,framedynos.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,fveapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fveapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fveskybackup.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,fvewiz.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,fwbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwbase.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwpolicyiomgr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwpolicyiomgr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwpuclnt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fwpuclnt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fxsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fxsapi.dll,*\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fxsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fxsst.dll,*\Windows\System32\*,T1574.001,https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/
|
||||
TRUE,fxstiff.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,fxstiff.dll,*\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,getuname.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,getuname.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,gflagsui.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Tools*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
|
||||
TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Workstation*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
|
||||
TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Player*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
|
||||
TRUE,gpapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,gpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,hha.dll,*\Windows\System32\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
|
||||
TRUE,hha.dll,*\Windows\SysWOW64\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
|
||||
TRUE,hha.dll,*\Program Files\HTML Help Workshop*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
|
||||
TRUE,hid.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,hid.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,hnetmon.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,hnetmon.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,hpcustpartui.dll,*\Program Files\HP*,T1574.002,https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html
|
||||
TRUE,hpqhvsei.dll,*\Program Files\HP*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,httpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,httpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,icmp.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,icmp.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,idstore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,idstore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ieadvpack.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ieadvpack.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iedkcs32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iedkcs32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iernonce.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
|
||||
TRUE,iernonce.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
|
||||
TRUE,iertutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iertutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ifmon.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ifmon.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ifsutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,ifsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,inproclogger.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iphlpapi.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iphlpapi.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iri.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iri.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iscsidsc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iscsidsc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iscsiexe.dll,*\Windows\System32\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
|
||||
TRUE,iscsiexe.dll,*\Windows\SysWOW64\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
|
||||
TRUE,iscsium.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iscsium.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,isv.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,isv.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,iumbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,iumsdk.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,joinutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,joinutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,kdstub.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ksuser.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ksuser.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ktmw32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ktmw32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ldvpocx.ocx,*\Program Files\Symantec_Client_Security\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
|
||||
TRUE,ldvpocx.ocx,*\Program Files\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
|
||||
TRUE,libvlc.dll,*\Program Files\VideoLAN\VLC*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
|
||||
TRUE,licensemanagerapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,licensemanagerapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,licensingdiagspp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,licensingdiagspp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,linkinfo.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,linkinfo.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619
|
||||
TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn\x86*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619
|
||||
TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn\x64*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619
|
||||
TRUE,loadperf.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,loadperf.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,lockdown.dll,*\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://twitter.com/thepacketrat/status/1520878930449817600
|
||||
TRUE,lockhostingframework.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,log.dll,*\Program Files\Bitdefender Antivirus Free*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,logoncli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,logoncli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,logoncontroller.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,logoncontroller.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,lpksetupproxyserv.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,lpksetupproxyserv.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,lrwizdll.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,magnification.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,magnification.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,maintenanceui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mapistub.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mapistub.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mbaexmlparser.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,mdmdiagnostics.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mfc42u.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,mfc42u.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,mfcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mfcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mfplat.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mfplat.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,midimap.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,midimap.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mintdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,miutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,miutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mlang.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mlang.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mmdevapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mmdevapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mobilenetworking.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mobilenetworking.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mozglue.dll,*\Program Files\SeaMonkey*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,mozglue.dll,*\Program Files\Mozilla Firefox*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,mozglue.dll,*\Program Files\Mozilla Thunderbird*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,mozglue.dll,*\AppData\Local\Mozilla Firefox\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,mpclient.dll,*\Program Files\Windows Defender*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
|
||||
TRUE,mpclient.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
|
||||
TRUE,mpr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,mpr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,mprapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mprapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mpsvc.dll,*\Program Files\Windows Defender\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
|
||||
TRUE,mpsvc.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
|
||||
TRUE,mrmcorer.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mrmcorer.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msacm32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msacm32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mscms.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mscms.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mscoree.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mscoree.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mscorsvc.dll,*\Windows\Microsoft.NET\Framework\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,mscorsvc.dll,*\Windows\Microsoft.NET\Framework64\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,msctf.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,msctf.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,msctfmonitor.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msctfmonitor.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msdrm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msdrm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msdtctm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msftedit.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
|
||||
TRUE,msftedit.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
|
||||
TRUE,msi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msiso.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,msiso.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,msutb.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msutb.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,msvcp110_win.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,msvcp110_win.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,msvcr100.dll,*\Windows\System32\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,msvcr100.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,mswb7.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,mswb7.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,mswsock.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,mswsock.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,msxml3.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,msxml3.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,mtxclu.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,mtxclu.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,napinsp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,napinsp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ncrypt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ncrypt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ndfapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ndfapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netapi32.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,netapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,netid.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netid.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netiohlp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netiohlp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netjoin.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,netjoin.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,netplwiz.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netplwiz.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netprofm.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,netprofm.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,netprovfw.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,netprovfw.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,netsetupapi.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,netsetupapi.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,netshell.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netshell.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nettrace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,netutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,networkexplorer.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,networkexplorer.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,newdev.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,newdev.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ninput.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ninput.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nlaapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nlaapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nlansp_c.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,nlansp_c.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,npmproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,npmproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,nshhttp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nshhttp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nshipsec.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nshipsec.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nshwfp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,nshwfp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ntdsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ntdsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ntlanman.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ntlanman.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ntlmshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ntlmshared.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ntmarta.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ntmarta.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ntshrui.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ntshrui.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,nvsmartmax.dll,*\Program Files\NVIDIA Corporation\Display*,T1574.002,https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
|
||||
TRUE,oleacc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,oleacc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,omadmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,omadmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,onex.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,onex.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,opcservices.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,opcservices.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,opera_elf.dll,*\Appdata\local\programs\opera\*,T1574.002,https://twitter.com/ShitSecure/status/1566127363389329412
|
||||
TRUE,osbaseln.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,osbaseln.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,osksupport.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,osuninst.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,osuninst.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,outllib.dll,*\Program Files\Microsoft Office\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
|
||||
TRUE,outllib.dll,*\Program Files\Microsoft Office\Root\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
|
||||
TRUE,p2p.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,p2p.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,p2pnetsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,p2pnetsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,p9np.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,p9np.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,pcaui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,pcaui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,pdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,pdh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,peerdistsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,peerdistsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,pkeyhelper.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,pla.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,pla.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,playsndsrv.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,playsndsrv.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,pnrpnsp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,pnrpnsp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,policymanager.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,policymanager.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,polstore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,polstore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,powrprof.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,powrprof.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,printui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,printui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,prntvpt.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,prntvpt.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,profapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,profapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,propsys.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,propsys.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,proximitycommon.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,proximitycommon.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,proximityservicepal.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,prvdmofcomp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,prvdmofcomp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,puiapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,puiapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,python39.dll,*\Program Files\Python39*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,python39.dll,*\Appdata\local\Temp\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,python39.dll,*\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,python39.dll,*\Users\anaconda3*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330
|
||||
TRUE,qrt.dll,*\Program Files\F-Secure\Anti-Virus*,T1574.002,https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/
|
||||
TRUE,radcui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,radcui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rasapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rasapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rasdlg.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,rasdlg.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,rasgcw.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,rasgcw.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,rasman.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rasman.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rasmontr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rasmontr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rastls.dll,*\Program Files\Symantec\Network Connected Devices Auto Setup*,T1574.002,https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf
|
||||
TRUE,rcdll.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,reagent.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,reagent.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,regapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,regapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,reseteng.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,resetengine.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,resutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,resutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rjvplatform.dll,*\Windows\System32\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499
|
||||
TRUE,rjvplatform.dll,*\Windows\SysWOW64\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499
|
||||
TRUE,rmclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rmclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rpcnsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rpcnsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,rtutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rtutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rtworkq.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rtworkq.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,rzlog4cpp_logger.dll,*\Appdata\local\razer\InGameEngine\cache\RzFpsApplet*,T1574.002,https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
|
||||
TRUE,safestore32.dll,*\Program Files\Sophos\Sophos Anti-Virus*,T1574.002,https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf
|
||||
TRUE,samcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,samcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,samlib.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,samlib.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sapi_onecore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,sapi_onecore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,sas.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sas.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,scansetting.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,scansetting.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,scecli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,scecli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,schedcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,schedcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,secur32.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,secur32.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,security.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,security.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,sensapi.dll,*\Windows\System32\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792
|
||||
TRUE,sensapi.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792
|
||||
TRUE,shell32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,shell32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,shfolder.dll,*\Windows\System32\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226
|
||||
TRUE,shfolder.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226
|
||||
TRUE,siteadv.dll,*\Program Files\SiteAdvisor\*,T1574.002,https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf
|
||||
TRUE,slc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,slc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,smadhook32c.dll,*\Program Files\Smadav*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,snmpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,snmpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,spectrumsyncclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,spp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,spp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sppc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sppc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sppcext.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,sppcext.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,srclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,srclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,srcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,srmtrace.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,srmtrace.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,srpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,srpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,srvcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,srvcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ssp.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ssp.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ssp_isv.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,ssp_isv.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,sspicli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sspicli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ssshim.dll,*\Windows\System32\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410
|
||||
TRUE,ssshim.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410
|
||||
TRUE,staterepository.core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,staterepository.core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,structuredquery.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,structuredquery.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,sxshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,sxshared.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,symsrv.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,systemsettingsthresholdadminflowui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tbs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tbs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tdh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,textshaping.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,textshaping.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,timesync.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tmdbglog.dll,*\Program Files\Trend Micro\Titanium*,T1574.002,https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/
|
||||
TRUE,tosbtkbd.dll,*\Program Files\Toshiba\Bluetooth Toshiba Stack*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis
|
||||
TRUE,tpmcoreprovisioning.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,tpmcoreprovisioning.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,tquery.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tquery.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tsworkspace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,tsworkspace.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ttdrecord.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,ttdrecord.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,twext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,twext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,twinapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,twinapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,twinui.appcore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,twinui.appcore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,uianimation.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,uianimation.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,uiautomationcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uiautomationcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uireng.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uireng.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uiribbon.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,uiribbon.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,umpdc.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,umpdc.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,unattend.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,unityplayer.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
|
||||
TRUE,updatepolicy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,updatepolicy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,upshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,urlmon.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,urlmon.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,userenv.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,userenv.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,utildll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,utildll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uxinit.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uxinit.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uxtheme.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,uxtheme.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vaultcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vaultcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vdsutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,vdsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,vender.dll,*\Program Files\ASUS\GPU TweakII*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,vender.dll,*\Program Files\ASUS\VGA COM\*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,version.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,version.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
|
||||
TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
|
||||
TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
|
||||
TRUE,virtdisk.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,virtdisk.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
|
||||
TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application\*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
|
||||
TRUE,vntfxf32.dll,*\Program Files\Venta\VentaFax & Voice*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
|
||||
TRUE,vsodscpl.dll,*\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/
|
||||
TRUE,vssapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vssapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vsstrace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,vsstrace.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wbemprox.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wbemprox.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wbemsvc.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wbemsvc.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wcmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wcmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wcnnetsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wdi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wdi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wdscore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wdscore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,webservices.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,webservices.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wecapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wecapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wer.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wer.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wevtapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wevtapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,whhelper.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,whhelper.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wimgapi.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
|
||||
TRUE,wimgapi.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
|
||||
TRUE,wimgapi.dll,*\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
|
||||
TRUE,winbio.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,winbio.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,winbrand.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winbrand.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,windows.storage.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windows.storage.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windows.storage.search.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windows.storage.search.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windows.ui.immersive.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,windows.ui.immersive.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,windowscodecs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,windowscodecs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,windowscodecsext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windowscodecsext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windowsperformancerecordercontrol.dll,*\Program Files\windows kits\10\windows performance toolkit*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,windowsperformancerecordercontrol.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,windowsperformancerecordercontrol.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,windowsperformancerecorderui.dll,*\Program Files\Windows Kits\10\Windows Performance Toolkit*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,windowsudk.shellcommon.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,windowsudk.shellcommon.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,winhttp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winhttp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wininet.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wininet.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winipsec.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winipsec.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winmde.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winmm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winmm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winnsi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winnsi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winrnr.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,winrnr.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,winscard.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,winscard.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,winsqlite3.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winsqlite3.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winsta.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winsta.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,winsync.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,winsync.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,winutils.dll,*\Program Files\Palo Alto Networks\Traps*,T1574.002,https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
|
||||
TRUE,wkscli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wkscli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wlanapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wlanapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wlancfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wlancfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wldp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wldp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wlidprov.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wlidprov.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wmiclnt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wmiclnt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wmidcom.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wmidcom.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wmiutils.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wmiutils.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wmpdui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wmsgapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wmsgapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wofutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wofutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wpdshext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wpdshext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wsc.dll,*\Program Files\AVAST Software\Avast*,T1574.001,https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2
|
||||
TRUE,wscapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,wscapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,wsdapi.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,wsdapi.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
|
||||
TRUE,wshbth.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wshbth.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,wshelper.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wshelper.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wsmsvc.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,wsmsvc.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,wtsapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wtsapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wwancfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wwancfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wwapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,wwapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,xmllite.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,xmllite.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,xolehlp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,xolehlp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows
|
||||
TRUE,xpsservices.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,xpsservices.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/
|
||||
TRUE,xwizards.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,xwizards.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,xwtpw32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
TRUE,xwtpw32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables
|
||||
|
@@ -1,3 +0,0 @@
|
||||
image, repository
|
||||
devsecops/cat_dog_client, splunk/devsecops_poc
|
||||
devsecops/cat_dog_server, splunk/devsecops_poc
|
||||
|
@@ -1,47 +0,0 @@
|
||||
filename,originalFileName,netFile
|
||||
MSBuild.exe,MSBuild.exe,True
|
||||
ComSvcConfig.exe,ComSvcConfig.exe,True
|
||||
DfsrAdmin.exe,DfsrAdmin.exe,True
|
||||
dfsvc.exe,dfsvc.exe,True
|
||||
Microsoft.Workflow.Compiler.exe,Microsoft.Workflow.Compiler.exe,True
|
||||
SMSvcHost.exe,SMSvcHost.exe,True
|
||||
WsatConfig.exe,WsatConfig.exe,True
|
||||
AddInProcess.exe,AddInProcess.exe,True
|
||||
AddInProcess32.exe,AddInProcess32.exe,True
|
||||
AddInUtil.exe,AddInUtil.exe,True
|
||||
aspnet_compiler.exe,aspnet_compiler.exe,True
|
||||
aspnet_regbrowsers.exe,aspnet_regbrowsers.exe,True
|
||||
aspnet_regsql.exe,aspnet_regsql.exe,True
|
||||
CasPol.exe,CasPol.exe,True
|
||||
DataSvcUtil.exe,DataSvcUtil.exe,True
|
||||
EdmGen.exe,EdmGen.exe,True
|
||||
InstallUtil.exe,InstallUtil.exe,True
|
||||
jsc.exe,jsc.exe,True
|
||||
ngentask.exe,ngentask.exe,True
|
||||
ngen.exe,ngen.exe,True
|
||||
RegAsm.exe,RegAsm.exe,True
|
||||
RegSvcs.exe,RegSvcs.exe,True
|
||||
SDNBR.exe,SDNBR.exe,True
|
||||
acu.exe,acu.exe,True
|
||||
AppVStreamingUX.exe,,True
|
||||
dsac.exe,dsac.exe,True
|
||||
LbfoAdmin.exe,LBFOADMIN.EXE,True
|
||||
Microsoft.Uev.SyncController.exe,Microsoft.Uev.SyncController.exe,True
|
||||
mtedit.exe,mtedit.exe,True
|
||||
ScriptRunner.exe,ScriptRunner.exe,True
|
||||
ServerManager.exe,servermanager.dll,True
|
||||
stordiag.exe,stordiag.exe,True
|
||||
storeadm.exe,storeadm.exe,True
|
||||
tzsync.exe,tzsync.exe,True
|
||||
UevAgentPolicyGenerator.exe,UevAgentPolicyGenerator.exe,True
|
||||
UevAppMonitor.exe,UevAppMonitor.exe,True
|
||||
UevTemplateBaselineGenerator.exe,UevTemplateBaselineGenerator.exe,True
|
||||
UevTemplateConfigItemGenerator.exe,UevTemplateConfigItemGenerator.exe,True
|
||||
powershell_ise.exe,powershell_ise.EXE,True
|
||||
iediagcmd.exe,IEDiagCmd.exe,True
|
||||
XBox.TCUI.exe,XBox.TCUI.exe,True
|
||||
Microsoft.ActiveDirectory.WebServices.exe,Microsoft.ActiveDirectory.WebServices.exe,True
|
||||
iisual.exe,iisual.exe,True
|
||||
FileHistory.exe,FileHistory.exe,True
|
||||
SecureAssessmentBrowser.exe,SecureAssessmentBrowser.exe,True
|
||||
aspnet_regiis.exe,aspnet_regiis.exe,True
|
||||
|
@@ -1,15 +0,0 @@
|
||||
filename,nirsoftFile
|
||||
AdvancedRun.exe,True
|
||||
ChromePass.exe,True
|
||||
CredHistView.exe,True
|
||||
Dialupass.exe,True
|
||||
iepv.exe,True
|
||||
LostMyPassword.exe,True
|
||||
mailpv.exe,True
|
||||
mspass.exe,True
|
||||
netpass.exe,True
|
||||
PasswordFox.exe,True
|
||||
PasswordHashesView.exe,True
|
||||
PstPassword.exe,True
|
||||
RegHiveBackup.exe,True
|
||||
WebBrowserPassView.exe,True
|
||||
|
@@ -1,52 +0,0 @@
|
||||
file_name,suspicious
|
||||
*.avi.com,true
|
||||
*.avi.exe,true
|
||||
*.doc.com,true
|
||||
*.doc.exe,true
|
||||
*.docx.com,true
|
||||
*.docx.exe,true
|
||||
*.jpg.com,true
|
||||
*.jpg.exe,true
|
||||
*.jpeg.com,true
|
||||
*.jpeg.exe,true
|
||||
*.mpg.com,true
|
||||
*.mpg.exe,true
|
||||
*.mpg2.com,true
|
||||
*.mpg2.exe,true
|
||||
*.mpeg.com,true
|
||||
*.mpeg.exe,true
|
||||
*.pdf.com,true
|
||||
*.pdf.exe,true
|
||||
*.png.com,true
|
||||
*.png.exe,true
|
||||
*.ppt.com,true
|
||||
*.ppt.exe,true
|
||||
*.pptx.com,true
|
||||
*.pptx.exe,true
|
||||
*.swf.com,true
|
||||
*.swf.exe,true
|
||||
*.xls.com,true
|
||||
*.xls.exe,true
|
||||
*.xlsx.com,true
|
||||
*.xlsx.exe,true
|
||||
*.zip.com,true
|
||||
*.zip.exe,true
|
||||
*.bat,true
|
||||
*.chm,true
|
||||
*.com,true
|
||||
*.cmd,true
|
||||
*.cpl,true
|
||||
*.exe,true
|
||||
*.hlp,true
|
||||
*.hta,true
|
||||
*.jar,true
|
||||
*.js,true
|
||||
*.msi,true
|
||||
*.pif,true
|
||||
*.ps1,true
|
||||
*.rar,true
|
||||
*.reg,true
|
||||
*.scr,true
|
||||
*.vbe,true
|
||||
*.vbs,true
|
||||
*.wsf,true
|
||||
|
@@ -1,753 +0,0 @@
|
||||
filename,systemFile
|
||||
acu.exe,true
|
||||
AgentService.exe,true
|
||||
aitstatic.exe,true
|
||||
alg.exe,true
|
||||
AppHostRegistrationVerifier.exe,true
|
||||
appidcertstorecheck.exe,true
|
||||
appidpolicyconverter.exe,true
|
||||
appidtel.exe,true
|
||||
ApplicationFrameHost.exe,true
|
||||
ApplySettingsTemplateCatalog.exe,true
|
||||
AppVClient.exe,true
|
||||
AppVDllSurrogate.exe,true
|
||||
AppVNice.exe,true
|
||||
AppVStreamingUX.exe,true
|
||||
ARP.EXE,true
|
||||
at.exe,true
|
||||
AtBroker.exe,true
|
||||
attrib.exe,true
|
||||
audiodg.exe,true
|
||||
auditpol.exe,true
|
||||
AuthHost.exe,true
|
||||
autochk.exe,true
|
||||
autoconv.exe,true
|
||||
autofmt.exe,true
|
||||
AxInstUI.exe,true
|
||||
backgroundTaskHost.exe,true
|
||||
BackgroundTransferHost.exe,true
|
||||
bcastdvr.exe,true
|
||||
bcdboot.exe,true
|
||||
bcdedit.exe,true
|
||||
BioIso.exe,true
|
||||
bitsadmin.exe,true
|
||||
bootcfg.exe,true
|
||||
bootim.exe,true
|
||||
bridgeunattend.exe,true
|
||||
browser_broker.exe,true
|
||||
bthudtask.exe,true
|
||||
ByteCodeGenerator.exe,true
|
||||
cacls.exe,true
|
||||
calc.exe,true
|
||||
CameraSettingsUIHost.exe,true
|
||||
CastSrv.exe,true
|
||||
CertEnrollCtrl.exe,true
|
||||
certreq.exe,true
|
||||
certutil.exe,true
|
||||
change.exe,true
|
||||
changepk.exe,true
|
||||
charmap.exe,true
|
||||
CheckNetIsolation.exe,true
|
||||
chglogon.exe,true
|
||||
chgport.exe,true
|
||||
chgusr.exe,true
|
||||
chkdsk.exe,true
|
||||
chkntfs.exe,true
|
||||
choice.exe,true
|
||||
cipher.exe,true
|
||||
cleanmgr.exe,true
|
||||
cliconfg.exe,true
|
||||
clip.exe,true
|
||||
ClipUp.exe,true
|
||||
CloudExperienceHostBroker.exe,true
|
||||
CloudNotifications.exe,true
|
||||
CloudStorageWizard.exe,true
|
||||
cmd.exe,true
|
||||
cmdkey.exe,true
|
||||
cmdl32.exe,true
|
||||
cmmon32.exe,true
|
||||
cmstp.exe,true
|
||||
cofire.exe,true
|
||||
colorcpl.exe,true
|
||||
comp.exe,true
|
||||
compact.exe,true
|
||||
CompatTelRunner.exe,true
|
||||
CompMgmtLauncher.exe,true
|
||||
ComputerDefaults.exe,true
|
||||
Configure-SMRemoting.exe,true
|
||||
conhost.exe,true
|
||||
consent.exe,true
|
||||
control.exe,true
|
||||
convert.exe,true
|
||||
CredentialUIBroker.exe,true
|
||||
credwiz.exe,true
|
||||
cscript.exe,true
|
||||
csrss.exe,true
|
||||
ctfmon.exe,true
|
||||
cttune.exe,true
|
||||
cttunesvr.exe,true
|
||||
dasHost.exe,true
|
||||
DataExchangeHost.exe,true
|
||||
DataSenseLiveTileTask.exe,true
|
||||
dccw.exe,true
|
||||
dcgpofix.exe,true
|
||||
dcomcnfg.exe,true
|
||||
dcpromo.exe,true
|
||||
ddodiag.exe,true
|
||||
Defrag.exe,true
|
||||
DeviceCensus.exe,true
|
||||
DeviceEject.exe,true
|
||||
DeviceEnroller.exe,true
|
||||
DevicePairingWizard.exe,true
|
||||
DeviceProperties.exe,true
|
||||
DFDWiz.exe,true
|
||||
dfrgui.exe,true
|
||||
dfsrdiag.exe,true
|
||||
dialer.exe,true
|
||||
DIMC.exe,true
|
||||
diskpart.exe,true
|
||||
diskperf.exe,true
|
||||
diskraid.exe,true
|
||||
diskshadow.exe,true
|
||||
DiskSnapshot.exe,true
|
||||
Dism.exe,true
|
||||
dispdiag.exe,true
|
||||
DisplaySwitch.exe,true
|
||||
djoin.exe,true
|
||||
dllhost.exe,true
|
||||
dllhst3g.exe,true
|
||||
dmcertinst.exe,true
|
||||
dmcfghost.exe,true
|
||||
DmNotificationBroker.exe,true
|
||||
DmOmaCpMo.exe,true
|
||||
dnscacheugc.exe,true
|
||||
doskey.exe,true
|
||||
dpapimig.exe,true
|
||||
DpiScaling.exe,true
|
||||
dpnsvr.exe,true
|
||||
driverquery.exe,true
|
||||
drvcfg.exe,true
|
||||
drvinst.exe,true
|
||||
DsmUserTask.exe,true
|
||||
dsregcmd.exe,true
|
||||
dstokenclean.exe,true
|
||||
dvdplay.exe,true
|
||||
dwm.exe,true
|
||||
DWWIN.EXE,true
|
||||
dxdiag.exe,true
|
||||
Dxpserver.exe,true
|
||||
Eap3Host.exe,true
|
||||
EaseOfAccessDialog.exe,true
|
||||
easinvoker.exe,true
|
||||
EasPoliciesBrokerHost.exe,true
|
||||
EDPCleanup.exe,true
|
||||
edpnotify.exe,true
|
||||
efsui.exe,true
|
||||
EhStorAuthn.exe,true
|
||||
embeddedapplauncher.exe,true
|
||||
EmbeddedAppLauncherConfig.exe,true
|
||||
escUnattend.exe,true
|
||||
esentutl.exe,true
|
||||
eudcedit.exe,true
|
||||
eventcreate.exe,true
|
||||
eventvwr.exe,true
|
||||
expand.exe,true
|
||||
extrac32.exe,true
|
||||
fc.exe,true
|
||||
find.exe,true
|
||||
findstr.exe,true
|
||||
finger.exe,true
|
||||
fixmapi.exe,true
|
||||
fltMC.exe,true
|
||||
fodhelper.exe,true
|
||||
Fondue.exe,true
|
||||
fontdrvhost.exe,true
|
||||
fontview.exe,true
|
||||
forfiles.exe,true
|
||||
fsavailux.exe,true
|
||||
fsquirt.exe,true
|
||||
fsutil.exe,true
|
||||
ftp.exe,true
|
||||
GameBarPresenceWriter.exe,true
|
||||
GamePanel.exe,true
|
||||
GenValObj.exe,true
|
||||
getmac.exe,true
|
||||
gpresult.exe,true
|
||||
gpscript.exe,true
|
||||
gpupdate.exe,true
|
||||
grpconv.exe,true
|
||||
hdwwiz.exe,true
|
||||
help.exe,true
|
||||
HOSTNAME.EXE,true
|
||||
hvax64.exe,true
|
||||
hvix64.exe,true
|
||||
hvloader.exe,true
|
||||
hwrcomp.exe,true
|
||||
hwrreg.exe,true
|
||||
iashost.exe,true
|
||||
icacls.exe,true
|
||||
IcsEntitlementHost.exe,true
|
||||
icsunattend.exe,true
|
||||
ie4uinit.exe,true
|
||||
ieUnatt.exe,true
|
||||
iexpress.exe,true
|
||||
immersivetpmvscmgrsvr.exe,true
|
||||
InfDefaultInstall.exe,true
|
||||
InstallAgent.exe,true
|
||||
InstallAgentUserBroker.exe,true
|
||||
ipconfig.exe,true
|
||||
iscsicli.exe,true
|
||||
iscsicpl.exe,true
|
||||
isoburn.exe,true
|
||||
klist.exe,true
|
||||
ksetup.exe,true
|
||||
ktmutil.exe,true
|
||||
ktpass.exe,true
|
||||
label.exe,true
|
||||
LanguageComponentsInstallerComHandler.exe,true
|
||||
LaunchTM.exe,true
|
||||
LaunchWinApp.exe,true
|
||||
LbfoAdmin.exe,true
|
||||
LegacyNetUXHost.exe,true
|
||||
LicenseManagerShellext.exe,true
|
||||
licensingdiag.exe,true
|
||||
LicensingUI.exe,true
|
||||
LocationNotificationWindows.exe,true
|
||||
Locator.exe,true
|
||||
LockAppHost.exe,true
|
||||
LockScreenContentServer.exe,true
|
||||
lodctr.exe,true
|
||||
logagent.exe,true
|
||||
logman.exe,true
|
||||
logoff.exe,true
|
||||
LogonUI.exe,true
|
||||
lpkinstall.exe,true
|
||||
lpksetup.exe,true
|
||||
lpremove.exe,true
|
||||
LsaIso.exe,true
|
||||
lsass.exe,true
|
||||
Magnify.exe,true
|
||||
makecab.exe,true
|
||||
mavinject.exe,true
|
||||
MbaeParserTask.exe,true
|
||||
mblctr.exe,true
|
||||
mcbuilder.exe,true
|
||||
MDEServer.exe,true
|
||||
MDMAgent.exe,true
|
||||
MDMAppInstaller.exe,true
|
||||
MdmDiagnosticsTool.exe,true
|
||||
MdRes.exe,true
|
||||
MdSched.exe,true
|
||||
mfpmp.exe,true
|
||||
Microsoft.Uev.CscUnpinTool.exe,true
|
||||
Microsoft.Uev.SyncController.exe,true
|
||||
mmc.exe,true
|
||||
mobsync.exe,true
|
||||
mountvol.exe,true
|
||||
mpnotify.exe,true
|
||||
MpSigStub.exe,true
|
||||
MRINFO.EXE,true
|
||||
MRT-KB890830.exe,true
|
||||
MRT.exe,true
|
||||
MSchedExe.exe,true
|
||||
msconfig.exe,true
|
||||
msdt.exe,true
|
||||
msdtc.exe,true
|
||||
msfeedssync.exe,true
|
||||
msg.exe,true
|
||||
mshta.exe,true
|
||||
msiexec.exe,true
|
||||
msinfo32.exe,true
|
||||
mspaint.exe,true
|
||||
MsSpellCheckingHost.exe,true
|
||||
mstsc.exe,true
|
||||
mtstocom.exe,true
|
||||
MuiUnattend.exe,true
|
||||
MultiDigiMon.exe,true
|
||||
MusNotification.exe,true
|
||||
MusNotificationUx.exe,true
|
||||
Narrator.exe,true
|
||||
nbtstat.exe,true
|
||||
ndadmin.exe,true
|
||||
net.exe,true
|
||||
net1.exe,true
|
||||
netbtugc.exe,true
|
||||
netcfg.exe,true
|
||||
NetCfgNotifyObjectHost.exe,true
|
||||
netdom.exe,true
|
||||
NetEvtFwdr.exe,true
|
||||
NetHost.exe,true
|
||||
netiougc.exe,true
|
||||
Netplwiz.exe,true
|
||||
netsh.exe,true
|
||||
NETSTAT.EXE,true
|
||||
newdev.exe,true
|
||||
nltest.exe,true
|
||||
notepad.exe,true
|
||||
nslookup.exe,true
|
||||
ntoskrnl.exe,true
|
||||
ntprint.exe,true
|
||||
odbcad32.exe,true
|
||||
odbcconf.exe,true
|
||||
omadmclient.exe,true
|
||||
omadmprc.exe,true
|
||||
openfiles.exe,true
|
||||
OpenWith.exe,true
|
||||
OptionalFeatures.exe,true
|
||||
osk.exe,true
|
||||
PackagedCWALauncher.exe,true
|
||||
PackageInspector.exe,true
|
||||
PasswordOnWakeSettingFlyout.exe,true
|
||||
PATHPING.EXE,true
|
||||
pcalua.exe,true
|
||||
pcaui.exe,true
|
||||
pcwrun.exe,true
|
||||
perfmon.exe,true
|
||||
phoneactivate.exe,true
|
||||
PickerHost.exe,true
|
||||
PING.EXE,true
|
||||
PkgMgr.exe,true
|
||||
plasrv.exe,true
|
||||
PnPUnattend.exe,true
|
||||
pnputil.exe,true
|
||||
poqexec.exe,true
|
||||
powercfg.exe,true
|
||||
PresentationHost.exe,true
|
||||
PresentationSettings.exe,true
|
||||
prevhost.exe,true
|
||||
print.exe,true
|
||||
PrintBrmUi.exe,true
|
||||
PrintDialogHost.exe,true
|
||||
PrintDialogHost3D.exe,true
|
||||
printfilterpipelinesvc.exe,true
|
||||
PrintIsolationHost.exe,true
|
||||
printui.exe,true
|
||||
proquota.exe,true
|
||||
psr.exe,true
|
||||
pwlauncher.exe,true
|
||||
qappsrv.exe,true
|
||||
qprocess.exe,true
|
||||
query.exe,true
|
||||
quser.exe,true
|
||||
qwinsta.exe,true
|
||||
rasdial.exe,true
|
||||
rdpclip.exe,true
|
||||
rdpinit.exe,true
|
||||
rdpinput.exe,true
|
||||
RdpSa.exe,true
|
||||
RdpSaProxy.exe,true
|
||||
RdpSaUacHelper.exe,true
|
||||
rdpshell.exe,true
|
||||
rdpsign.exe,true
|
||||
rdrleakdiag.exe,true
|
||||
RDSPnf.exe,true
|
||||
ReAgentc.exe,true
|
||||
recover.exe,true
|
||||
RecoveryDrive.exe,true
|
||||
reg.exe,true
|
||||
regedt32.exe,true
|
||||
regini.exe,true
|
||||
Register-CimProvider.exe,true
|
||||
regsvr32.exe,true
|
||||
rekeywiz.exe,true
|
||||
relog.exe,true
|
||||
RelPost.exe,true
|
||||
RemotePosWorker.exe,true
|
||||
replace.exe,true
|
||||
reset.exe,true
|
||||
ResetEngine.exe,true
|
||||
resmon.exe,true
|
||||
RMActivate.exe,true
|
||||
RMActivate_isv.exe,true
|
||||
RMActivate_ssp.exe,true
|
||||
RMActivate_ssp_isv.exe,true
|
||||
RmClient.exe,true
|
||||
rmttpmvscmgrsvr.exe,true
|
||||
Robocopy.exe,true
|
||||
ROUTE.EXE,true
|
||||
RpcPing.exe,true
|
||||
rrinstaller.exe,true
|
||||
rsopprov.exe,true
|
||||
runas.exe,true
|
||||
rundll32.exe,true
|
||||
RunLegacyCPLElevated.exe,true
|
||||
runonce.exe,true
|
||||
RuntimeBroker.exe,true
|
||||
rwinsta.exe,true
|
||||
sacsess.exe,true
|
||||
sc.exe,true
|
||||
schtasks.exe,true
|
||||
ScriptRunner.exe,true
|
||||
sdbinst.exe,true
|
||||
sdiagnhost.exe,true
|
||||
SearchFilterHost.exe,true
|
||||
SearchIndexer.exe,true
|
||||
SearchProtocolHost.exe,true
|
||||
SecEdit.exe,true
|
||||
secinit.exe,true
|
||||
securekernel.exe,true
|
||||
SensorDataService.exe,true
|
||||
ServerManager.exe,true
|
||||
ServerManagerLauncher.exe,true
|
||||
services.exe,true
|
||||
sessionmsg.exe,true
|
||||
sethc.exe,true
|
||||
setres.exe,true
|
||||
setspn.exe,true
|
||||
SettingSyncHost.exe,true
|
||||
setupcl.exe,true
|
||||
setupugc.exe,true
|
||||
setx.exe,true
|
||||
sfc.exe,true
|
||||
shrpubw.exe,true
|
||||
shutdown.exe,true
|
||||
sigverif.exe,true
|
||||
SIHClient.exe,true
|
||||
sihost.exe,true
|
||||
SlideToShutDown.exe,true
|
||||
slui.exe,true
|
||||
smartscreen.exe,true
|
||||
SmartScreenSettings.exe,true
|
||||
smss.exe,true
|
||||
SndVol.exe,true
|
||||
SnippingTool.exe,true
|
||||
snmptrap.exe,true
|
||||
sort.exe,true
|
||||
SpaceAgent.exe,true
|
||||
spaceman.exe,true
|
||||
spoolsv.exe,true
|
||||
SppExtComObj.Exe,true
|
||||
sppsvc.exe,true
|
||||
stordiag.exe,true
|
||||
subst.exe,true
|
||||
svchost.exe,true
|
||||
sxstrace.exe,true
|
||||
SyncAppvPublishingServer.exe,true
|
||||
SyncHost.exe,true
|
||||
syskey.exe,true
|
||||
SysResetErr.exe,true
|
||||
systeminfo.exe,true
|
||||
SystemPropertiesAdvanced.exe,true
|
||||
SystemPropertiesComputerName.exe,true
|
||||
SystemPropertiesDataExecutionPrevention.exe,true
|
||||
SystemPropertiesHardware.exe,true
|
||||
SystemPropertiesPerformance.exe,true
|
||||
SystemPropertiesProtection.exe,true
|
||||
SystemPropertiesRemote.exe,true
|
||||
systemreset.exe,true
|
||||
SystemSettingsAdminFlows.exe,true
|
||||
SystemSettingsBroker.exe,true
|
||||
SystemSettingsRemoveDevice.exe,true
|
||||
systray.exe,true
|
||||
tabcal.exe,true
|
||||
takeown.exe,true
|
||||
TapiUnattend.exe,true
|
||||
taskhostw.exe,true
|
||||
taskkill.exe,true
|
||||
tasklist.exe,true
|
||||
Taskmgr.exe,true
|
||||
tcmsetup.exe,true
|
||||
TCPSVCS.EXE,true
|
||||
tdlrecover.exe,true
|
||||
ThumbnailExtractionHost.exe,true
|
||||
TieringEngineService.exe,true
|
||||
timeout.exe,true
|
||||
TokenBrokerCookies.exe,true
|
||||
TpmInit.exe,true
|
||||
tpmvscmgr.exe,true
|
||||
tpmvscmgrsvr.exe,true
|
||||
tracerpt.exe,true
|
||||
TRACERT.EXE,true
|
||||
tscon.exe,true
|
||||
tsdiscon.exe,true
|
||||
tsecimp.exe,true
|
||||
tskill.exe,true
|
||||
TSTheme.exe,true
|
||||
TSWbPrxy.exe,true
|
||||
typeperf.exe,true
|
||||
tzsync.exe,true
|
||||
tzutil.exe,true
|
||||
ucsvc.exe,true
|
||||
UevAgentPolicyGenerator.exe,true
|
||||
UevAppMonitor.exe,true
|
||||
UevTemplateBaselineGenerator.exe,true
|
||||
UevTemplateConfigItemGenerator.exe,true
|
||||
UI0Detect.exe,true
|
||||
unlodctr.exe,true
|
||||
unregmp2.exe,true
|
||||
UpgradeResultsUI.exe,true
|
||||
upnpcont.exe,true
|
||||
UserAccountBroker.exe,true
|
||||
UserAccountControlSettings.exe,true
|
||||
userinit.exe,true
|
||||
UsoClient.exe,true
|
||||
Utilman.exe,true
|
||||
VaultCmd.exe,true
|
||||
vds.exe,true
|
||||
vdsldr.exe,true
|
||||
verclsid.exe,true
|
||||
verifier.exe,true
|
||||
verifiergui.exe,true
|
||||
vssadmin.exe,true
|
||||
VSSUIRUN.exe,true
|
||||
VSSVC.exe,true
|
||||
w32tm.exe,true
|
||||
waitfor.exe,true
|
||||
WallpaperHost.exe,true
|
||||
WebCache.exe,true
|
||||
wecutil.exe,true
|
||||
WerFault.exe,true
|
||||
WerFaultSecure.exe,true
|
||||
wermgr.exe,true
|
||||
wevtutil.exe,true
|
||||
wextract.exe,true
|
||||
where.exe,true
|
||||
whoami.exe,true
|
||||
wiaacmgr.exe,true
|
||||
wiawow64.exe,true
|
||||
wimserv.exe,true
|
||||
win32calc.exe,true
|
||||
WinBioDataModelOOBE.exe,true
|
||||
Windows.Media.BackgroundPlayback.exe,true
|
||||
WindowsActionDialog.exe,true
|
||||
WindowsUpdateElevatedInstaller.exe,true
|
||||
wininit.exe,true
|
||||
winload.exe,true
|
||||
winlogon.exe,true
|
||||
winresume.exe,true
|
||||
winrs.exe,true
|
||||
winrshost.exe,true
|
||||
WinSAT.exe,true
|
||||
winver.exe,true
|
||||
wkspbroker.exe,true
|
||||
wksprt.exe,true
|
||||
wlrmdr.exe,true
|
||||
WMPDMC.exe,true
|
||||
wowreg32.exe,true
|
||||
WPDShextAutoplay.exe,true
|
||||
wpr.exe,true
|
||||
write.exe,true
|
||||
WSCollect.exe,true
|
||||
wscript.exe,true
|
||||
WSManHTTPConfig.exe,true
|
||||
wsmprovhost.exe,true
|
||||
wsqmcons.exe,true
|
||||
WSReset.exe,true
|
||||
wuapihost.exe,true
|
||||
wuauclt.exe,true
|
||||
WUDFHost.exe,true
|
||||
wusa.exe,true
|
||||
WWAHost.exe,true
|
||||
XblGameSaveTask.exe,true
|
||||
xcopy.exe,true
|
||||
xwizard.exe,true
|
||||
comrepl.exe,true
|
||||
MigRegDB.exe,true
|
||||
DiagnosticsHub.StandardCollector.Service.exe,true
|
||||
DismHost.exe,true
|
||||
F12Chooser.exe,true
|
||||
IMJPDCT.EXE,true
|
||||
IMJPSET.EXE,true
|
||||
IMJPUEX.EXE,true
|
||||
imjpuexc.exe,true
|
||||
IMTCLNWZ.EXE,true
|
||||
IMTCPROP.exe,true
|
||||
IMCCPHR.exe,true
|
||||
ImeBroker.exe,true
|
||||
imecfmui.exe,true
|
||||
IMEDICTUPDATEUI.EXE,true
|
||||
IMEPADSV.EXE,true
|
||||
IMESEARCH.EXE,true
|
||||
IMEWDBLD.EXE,true
|
||||
ChsIME.exe,true
|
||||
ChtIME.exe,true
|
||||
mighost.exe,true
|
||||
audit.exe,true
|
||||
AuditShD.exe,true
|
||||
FirstLogonAnim.exe,true
|
||||
msoobe.exe,true
|
||||
oobeldr.exe,true
|
||||
Setup.exe,true
|
||||
UserOOBEBroker.exe,true
|
||||
windeploy.exe,true
|
||||
SpeechUXWiz.exe,true
|
||||
SpeechModelDownload.exe,true
|
||||
SpeechRuntime.exe,true
|
||||
PrintBrm.exe,true
|
||||
PrintBrmEngine.exe,true
|
||||
sysprep.exe,true
|
||||
SystemResetPlatform.exe,true
|
||||
mofcomp.exe,true
|
||||
scrcons.exe,true
|
||||
unsecapp.exe,true
|
||||
wbemtest.exe,true
|
||||
WinMgmt.exe,true
|
||||
WMIADAP.exe,true
|
||||
WmiApSrv.exe,true
|
||||
WMIC.exe,true
|
||||
WmiPrvSE.exe,true
|
||||
powershell.exe,true
|
||||
powershell_ise.exe,true
|
||||
dplaysvr.exe,true
|
||||
dtdump.exe,true
|
||||
hh.exe,true
|
||||
instnm.exe,true
|
||||
perfhost.exe,true
|
||||
rasautou.exe,true
|
||||
rasphone.exe,true
|
||||
regedit.exe,true
|
||||
setup16.exe,true
|
||||
user.exe,true
|
||||
_isdel.exe,true
|
||||
agentactivationruntimestarter.exe,true
|
||||
ApplyTrustOffline.exe,true
|
||||
ApproveChildRequest.exe,true
|
||||
appverif.exe,true
|
||||
baaupdate.exe,true
|
||||
bash.exe,true
|
||||
bdechangepin.exe,true
|
||||
BdeHdCfg.exe,true
|
||||
BdeUISrv.exe,true
|
||||
bdeunlock.exe,true
|
||||
BitLockerDeviceEncryption.exe,true
|
||||
BitLockerWizard.exe,true
|
||||
BitLockerWizardElev.exe,true
|
||||
bootsect.exe,true
|
||||
browserexport.exe,true
|
||||
CIDiag.exe,true
|
||||
CompPkgSrv.exe,true
|
||||
convertvhd.exe,true
|
||||
coredpussvr.exe,true
|
||||
CredentialEnrollmentManager.exe,true
|
||||
curl.exe,true
|
||||
CustomInstallExec.exe,true
|
||||
d3dconfig.exe,true
|
||||
DataStoreCacheDumpTool.exe,true
|
||||
DataUsageLiveTileTask.exe,true
|
||||
deploymentcsphelper.exe,true
|
||||
desktopimgdownldr.exe,true
|
||||
DeviceCredentialDeployment.exe,true
|
||||
directxdatabaseupdater.exe,true
|
||||
dmclient.exe,true
|
||||
DTUHandler.exe,true
|
||||
dusmtask.exe,true
|
||||
DXCap.exe,true
|
||||
DXCpl.exe,true
|
||||
dxgiadaptercache.exe,true
|
||||
EASPolicyManagerBrokerHost.exe,true
|
||||
EduPrintProv.exe,true
|
||||
EoAExperiences.exe,true
|
||||
fhmanagew.exe,true
|
||||
FileHistory.exe,true
|
||||
FsIso.exe,true
|
||||
fvenotify.exe,true
|
||||
fveprompt.exe,true
|
||||
FXSCOVER.exe,true
|
||||
FXSSVC.exe,true
|
||||
FXSUNATD.exe,true
|
||||
hcsdiag.exe,true
|
||||
hnsdiag.exe,true
|
||||
hvsievaluator.exe,true
|
||||
ie4ushowIE.exe,true
|
||||
IESettingSync.exe,true
|
||||
InputSwitchToastHandler.exe,true
|
||||
iotstartup.exe,true
|
||||
manage-bde.exe,true
|
||||
MBR2GPT.EXE,true
|
||||
microsoft.windows.softwarelogo.showdesktop.exe,true
|
||||
MicrosoftEdgeBCHost.exe,true
|
||||
MicrosoftEdgeCP.exe,true
|
||||
MicrosoftEdgeDevTools.exe,true
|
||||
MicrosoftEdgeSH.exe,true
|
||||
mmgaserver.exe,true
|
||||
MoUsoCoreWorker.exe,true
|
||||
msra.exe,true
|
||||
MusNotifyIcon.exe,true
|
||||
NDKPing.exe,true
|
||||
NgcIso.exe,true
|
||||
nmbind.exe,true
|
||||
nmscrub.exe,true
|
||||
nvspinfo.exe,true
|
||||
ofdeploy.exe,true
|
||||
pacjsworker.exe,true
|
||||
PinEnrollmentBroker.exe,true
|
||||
PktMon.exe,true
|
||||
pospaymentsworker.exe,true
|
||||
provlaunch.exe,true
|
||||
provtool.exe,true
|
||||
ProximityUxHost.exe,true
|
||||
prproc.exe,true
|
||||
quickassist.exe,true
|
||||
raserver.exe,true
|
||||
RDVGHelper.exe,true
|
||||
recdisc.exe,true
|
||||
refsutil.exe,true
|
||||
RemoteAppLifetimeManager.exe,true
|
||||
RemoteFXvGPUDisablement.exe,true
|
||||
repair-bde.exe,true
|
||||
rstrui.exe,true
|
||||
runexehelper.exe,true
|
||||
sdchange.exe,true
|
||||
sdclt.exe,true
|
||||
SecurityHealthHost.exe,true
|
||||
SecurityHealthService.exe,true
|
||||
SecurityHealthSystray.exe,true
|
||||
SgrmBroker.exe,true
|
||||
SgrmLpac.exe,true
|
||||
SpatialAudioLicenseSrv.exe,true
|
||||
Spectrum.exe,true
|
||||
srdelayed.exe,true
|
||||
SrTasks.exe,true
|
||||
SystemUWPLauncher.exe,true
|
||||
tar.exe,true
|
||||
tcblaunch.exe,true
|
||||
TpmTool.exe,true
|
||||
ttdinject.exe,true
|
||||
tttracer.exe,true
|
||||
UIMgrBroker.exe,true
|
||||
upfc.exe,true
|
||||
usocoreworker.exe,true
|
||||
UtcDecoderHost.exe,true
|
||||
VBoxControl.exe,true
|
||||
VBoxService.exe,true
|
||||
VBoxTray.exe,true
|
||||
vfpctrl.exe,true
|
||||
vmcompute.exe,true
|
||||
vmwp.exe,true
|
||||
VsGraphicsDesktopEngine.exe,true
|
||||
VsGraphicsRemoteEngine.exe,true
|
||||
vsjitdebugger.exe,true
|
||||
WaaSMedicAgent.exe,true
|
||||
wbadmin.exe,true
|
||||
wbengine.exe,true
|
||||
WFS.exe,true
|
||||
wifitask.exe,true
|
||||
Windows.WARP.JITService.exe,true
|
||||
WinRTNetMUAHostServer.exe,true
|
||||
wlanext.exe,true
|
||||
WorkFolders.exe,true
|
||||
WpcMon.exe,true
|
||||
WpcTok.exe,true
|
||||
wpnpinst.exe,true
|
||||
wscadminui.exe,true
|
||||
wsl.exe,true
|
||||
wslconfig.exe,true
|
||||
WUDFCompanionHost.exe,true
|
||||
IEChooser.exe,true
|
||||
wslhost.exe,true
|
||||
scp.exe,true
|
||||
sftp.exe,true
|
||||
ssh-add.exe,true
|
||||
ssh-agent.exe,true
|
||||
ssh-keygen.exe,true
|
||||
ssh-keyscan.exe,true
|
||||
ssh.exe,true
|
||||
PerceptionSimulationInput.exe,true
|
||||
PerceptionSimulationService.exe,true
|
||||
UNPUXHost.exe,true
|
||||
UNPUXLauncher.exe,true
|
||||
UpdateNotificationMgr.exe,true
|
||||
FaceFodUninstaller.exe,true
|
||||
wlms.exe,true
|
||||
OneDriveSetup.exe,true
|
||||
OposHost.exe,true
|
||||
|
@@ -1,20 +0,0 @@
|
||||
domain, isLegit
|
||||
amazon.com, True
|
||||
ssl-images-amazon.com, True
|
||||
facebook.com, True
|
||||
xx.fbcdn.net, True
|
||||
github.com, True
|
||||
githubassets.com, True
|
||||
instagram.com, True
|
||||
linkedin.com, True
|
||||
microsoftonline.com, True
|
||||
office.com, True
|
||||
okta.com, True
|
||||
live.com, True
|
||||
protonmail.com, True
|
||||
reddit.com, True
|
||||
redditstatic.com, True
|
||||
twitter.com, True
|
||||
twimg.com, True
|
||||
google.com, True
|
||||
|
||||
|
@@ -1,61 +0,0 @@
|
||||
process
|
||||
cat /proc/version
|
||||
cat /etc/*-release
|
||||
/etc/passwd
|
||||
cat /etc/*
|
||||
lastlog
|
||||
id
|
||||
PermitRootLogin
|
||||
sestatus *
|
||||
ps
|
||||
mysql*
|
||||
netstat*
|
||||
find *
|
||||
head /var/mail/root
|
||||
docker
|
||||
cat /etc/issue
|
||||
cat /etc/*-release
|
||||
cat /proc/version
|
||||
uname -a
|
||||
uname -mrs
|
||||
rpm -q kernel
|
||||
dmesg | grep Linux
|
||||
ls /boot | grep vmlinuz-
|
||||
cat /etc/profile
|
||||
cat /etc/bashrc
|
||||
cat ~/.bash_profile
|
||||
cat ~/.bashrc
|
||||
cat ~/.bash_logout
|
||||
ps -aux | grep root
|
||||
ps -ef | grep root
|
||||
crontab -l
|
||||
cat /etc/cron*
|
||||
cat /etc/cron.allow
|
||||
cat /etc/cron.deny
|
||||
cat /etc/crontab
|
||||
grep -i user *
|
||||
grep -i pass *
|
||||
ifconfig
|
||||
cat /etc/network/interfaces
|
||||
cat /etc/sysconfig/network
|
||||
cat /etc/resolv.conf
|
||||
cat /etc/networks
|
||||
cvelist-file:*
|
||||
exploit-db*
|
||||
strings -e /etc/apache2/apache2.conf
|
||||
strings -e /etc/ssh/sshd_config
|
||||
strings -e /etc/shadow
|
||||
iptables -L
|
||||
lsof -i
|
||||
netstat -antup
|
||||
netstat -antpx
|
||||
netstat -tulpn
|
||||
arp -e
|
||||
route
|
||||
cat /etc/passwd
|
||||
cat /etc/group
|
||||
cat /etc/shadow
|
||||
find / -perm -u=s
|
||||
find / -perm -g=s
|
||||
find / -perm -4000
|
||||
find / -perm -2000
|
||||
|
File diff suppressed because it is too large
Load Diff
@@ -1,480 +0,0 @@
|
||||
lolbas_file_name,lolbas_file_path,description
|
||||
eventvwr.exe,c:\windows\system32\*,Displays Windows Event Logs in a GUI window.
|
||||
eventvwr.exe,c:\windows\syswow64\*,Displays Windows Event Logs in a GUI window.
|
||||
rasautou.exe,c:\windows\system32\*,Windows Remote Access Dialer
|
||||
regedit.exe,c:\windows\system32\*,Used by Windows to manipulate registry
|
||||
regedit.exe,c:\windows\syswow64\*,Used by Windows to manipulate registry
|
||||
regsvr32.exe,c:\windows\system32\*,Used by Windows to register dlls
|
||||
regsvr32.exe,c:\windows\syswow64\*,Used by Windows to register dlls
|
||||
control.exe,c:\windows\system32\*,Binary used to launch controlpanel items in Windows
|
||||
control.exe,c:\windows\syswow64\*,Binary used to launch controlpanel items in Windows
|
||||
configsecuritypolicy.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
|
||||
scriptrunner.exe,c:\windows\system32\*,Execute binary through proxy binary to evade defensive counter measures
|
||||
scriptrunner.exe,c:\windows\syswow64\*,Execute binary through proxy binary to evade defensive counter measures
|
||||
offlinescannershell.exe,c:\program files\windows defender\offline\*,Windows Defender Offline Shell
|
||||
atbroker.exe,c:\windows\system32\*,Helper binary for Assistive Technology (AT)
|
||||
atbroker.exe,c:\windows\syswow64\*,Helper binary for Assistive Technology (AT)
|
||||
mmc.exe,c:\windows\system32\*,Load snap-ins to locally and remotely manage Windows systems
|
||||
mmc.exe,c:\windows\syswow64\*,Load snap-ins to locally and remotely manage Windows systems
|
||||
mavinject.exe,c:\windows\system32\*,Used by App-v in Windows
|
||||
mavinject.exe,c:\windows\syswow64\*,Used by App-v in Windows
|
||||
ftp.exe,c:\windows\system32\*,A binary designed for connecting to FTP servers
|
||||
ftp.exe,c:\windows\syswow64\*,A binary designed for connecting to FTP servers
|
||||
ttdinject.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
|
||||
ttdinject.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
|
||||
certoc.exe,c:\windows\system32\*,Used for installing certificates
|
||||
certoc.exe,c:\windows\syswow64\*,Used for installing certificates
|
||||
at.exe,c:\windows\system32\*,Schedule periodic tasks
|
||||
at.exe,c:\windows\syswow64\*,Schedule periodic tasks
|
||||
netsh.exe,c:\windows\system32\*,Netsh is a Windows tool used to manipulate network interface settings.
|
||||
netsh.exe,c:\windows\syswow64\*,Netsh is a Windows tool used to manipulate network interface settings.
|
||||
pnputil.exe,c:\windows\system32\*,Used for installing drivers
|
||||
ie4uinit.exe,c:\windows\system32\*,Executes commands from a specially prepared ie4uinit.inf file.
|
||||
ie4uinit.exe,c:\windows\syswow64\*,Executes commands from a specially prepared ie4uinit.inf file.
|
||||
infdefaultinstall.exe,c:\windows\system32\*,Binary used to perform installation based on content inside inf files
|
||||
infdefaultinstall.exe,c:\windows\syswow64\*,Binary used to perform installation based on content inside inf files
|
||||
forfiles.exe,c:\windows\system32\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
|
||||
forfiles.exe,c:\windows\syswow64\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
|
||||
register-cimprovider.exe,c:\windows\system32\*,Used to register new wmi providers
|
||||
register-cimprovider.exe,c:\windows\syswow64\*,Used to register new wmi providers
|
||||
tttracer.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel
|
||||
tttracer.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel
|
||||
xwizard.exe,c:\windows\system32\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
|
||||
xwizard.exe,c:\windows\syswow64\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
|
||||
pcalua.exe,c:\windows\system32\*,Program Compatibility Assistant
|
||||
print.exe,c:\windows\system32\*,Used by Windows to send files to the printer
|
||||
print.exe,c:\windows\syswow64\*,Used by Windows to send files to the printer
|
||||
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\*,Execute target PowerShell script
|
||||
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\*,Execute target PowerShell script
|
||||
regasm.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Part of .NET
|
||||
regasm.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Part of .NET
|
||||
regasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Part of .NET
|
||||
regasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Part of .NET
|
||||
cmd.exe,c:\windows\system32\*,The command-line interpreter in Windows
|
||||
cmd.exe,c:\windows\syswow64\*,The command-line interpreter in Windows
|
||||
msbuild.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Used to compile and execute code
|
||||
msbuild.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Used to compile and execute code
|
||||
msbuild.exe,c:\windows\microsoft.net\framework\v3.5\*,Used to compile and execute code
|
||||
msbuild.exe,c:\windows\microsoft.net\framework64\v3.5\*,Used to compile and execute code
|
||||
msbuild.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Used to compile and execute code
|
||||
msbuild.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Used to compile and execute code
|
||||
msbuild.exe,c:\program files (x86)\msbuild\14.0\bin\*,Used to compile and execute code
|
||||
certutil.exe,c:\windows\system32\*,Windows binary used for handling certificates
|
||||
certutil.exe,c:\windows\syswow64\*,Windows binary used for handling certificates
|
||||
vbc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used for compile vbs code
|
||||
vbc.exe,c:\windows\microsoft.net\framework64\v3.5\*,Binary file used for compile vbs code
|
||||
psr.exe,c:\windows\system32\*,"Windows Problem Steps Recorder, used to record screen and clicks."
|
||||
psr.exe,c:\windows\syswow64\*,"Windows Problem Steps Recorder, used to record screen and clicks."
|
||||
extexport.exe,c:\program files\internet explorer\*,Load a DLL located in the c:\test folder with a specific name.
|
||||
extexport.exe,c:\program files (x86)\internet explorer\*,Load a DLL located in the c:\test folder with a specific name.
|
||||
rpcping.exe,c:\windows\system32\*,Used to verify rpc connection
|
||||
rpcping.exe,c:\windows\syswow64\*,Used to verify rpc connection
|
||||
msdt.exe,c:\windows\system32\*,Microsoft diagnostics tool
|
||||
msdt.exe,c:\windows\syswow64\*,Microsoft diagnostics tool
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\64kb6472.inf_amd64_3daef03bbe98572b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_0e9c57ae3396e055\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_209bd95d56b1ac2d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_3fa2a843f8b7f16d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_85c860f05274baa0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_f7412e3e3404de80\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_feb9f1cf05b0de58\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_component.inf_amd64_0219cc1c7085a93f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_component.inf_amd64_df4f60b1cae9b14a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_16eb18b0e2526e57\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_1c77f1231c19bc72\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_31c60cc38cfcca28\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_82f69cea8b2d928f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dc_comp.inf_amd64_b4d94f3e41ceb839\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_0606619cc97463de\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_0e95edab338ad669\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_22aac1442d387216\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_2461d914696db722\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_29d727269a34edf5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_2caf76dbce56546d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_353320edb98da643\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_4ea0ed0af1507894\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_56a48f4f1c2da7a7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_64f23fdadb76a511\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_668dd0c6d3f9fa0e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6be8e5b7f731a6e5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6dad7e4e9a8fa889\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_6df442103a1937a4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_767e7683f9ad126c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_8644298f665a12c4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_868acf86149aef5d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_92cf9d9d84f1d3db\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_93239c65f222d453\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_9de8154b682af864\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_a7428663aca90897\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_ad7cb5e55a410add\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_afbf41cf8ab202d7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_d193c96475eaa96e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_db953c52208ada71\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_e7523682cc7528cc\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_e9f341319ca84274\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_f3a64c75ee4defb7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch.inf_amd64_f51939e52b944f4b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_4938423c9b9639d7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_c8e108d4a62c59d5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_dch_comp.inf_amd64_deecec7d232ced2b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_01ee1299f4982efe\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_02edfc87000937e4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0541b698fc6e40b0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0707757077710fff\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_0cff362f9dff4228\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_16ed7d82b93e4f68\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1a33d2f73651d989\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1aca2a92a37fce23\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1af2dd3e4df5fd61\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_1d571527c7083952\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_23f7302c2b9ee813\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_24de78387e6208e4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_250db833a1cd577e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_25e7c5a58c052bc5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_28d80681d3523b1c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_2dda3b1147a3a572\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_31ba00ea6900d67d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_329877a66f240808\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_42af9f4718aa1395\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_4645af5c659ae51a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_48c2e68e54c92258\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_48e7e903a369eae2\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_491d20003583dabe\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_4b34c18659561116\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_51ce968bf19942c2\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_555cfc07a674ecdd\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_561bd21d54545ed3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_579a75f602cc2dce\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_57f66a4f0a97f1a3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_587befb80671fb38\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_62f096fe77e085c0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6ae0ddbb4a38e23c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6bb02522ea3fdb0d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_6d34ac0763025a06\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_712b6a0adbaabc0a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_78b09d9681a2400f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_842874489af34daa\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_88084eb1fe7cebc3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_89033455cb08186f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_8a9535cd18c90bc3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_8c1fc948b5a01c52\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_9088b61921a6ff9f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_90f68cd0dc48b625\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_95cb371d046d4b4c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_a58de0cf5f3e9dca\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_abe9d37302f8b1ae\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_acb3edda7b82982f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_aebc5a8535dd3184\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_b5d4c82c67b39358\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_b846bbf1e81ea3cf\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_babb2e8b8072ff3b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_bc75cebf5edbbc50\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_be91293cf20d4372\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c11f4d5f0bc4c592\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c4e5173126d31cf0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c4f600ffe34acc7b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c8634ed19e331cda\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_c9081e50bcffa972\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_ceddadac8a2b489e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d4406f0ad6ec2581\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d5877a2e0e6374b6\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_d8ca5f86add535ef\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_e8abe176c7b553b5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_eabb3ac2c517211f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_f8d8be8fea71e1a0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_fe5e116bb07c0629\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64.inf_amd64_fe73d2ebaa05fb95\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\igdlh64_kbl_kit127397.inf_amd64_e1da8ee9e92ccadb\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\k127153.inf_amd64_364f43f2a27f7bd7\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\k127153.inf_amd64_3f3936d8dec668b8\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\k127793.inf_amd64_3ab7883eddccbf0f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129523.inf_amd64_32947eecf8f3e231\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126950.inf_amd64_fa7f56314967630d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126951.inf_amd64_94804e3918169543\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126973.inf_amd64_06dde156632145e3\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki126974.inf_amd64_9168fc04b8275db9\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127005.inf_amd64_753576c4406c1193\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127018.inf_amd64_0f67ff47e9e30716\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127021.inf_amd64_0d68af55c12c7c17\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127171.inf_amd64_368f8c7337214025\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127176.inf_amd64_86c658cabfb17c9c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127390.inf_amd64_e1ccb879ece8f084\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127678.inf_amd64_8427d3a09f47dfc1\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127727.inf_amd64_cf8e31692f82192e\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127807.inf_amd64_fc915899816dbc5d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki127850.inf_amd64_6ad8d99023b59fd5\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki128602.inf_amd64_6ff790822fd674ab\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki128916.inf_amd64_3509e1eb83b83cfb\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129407.inf_amd64_f26f36ac54ce3076\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129633.inf_amd64_d9b8af875f664a8c\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki129866.inf_amd64_e7cdca9882c16f55\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130274.inf_amd64_bafd2440fa1ffdd6\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130350.inf_amd64_696b7c6764071b63\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130409.inf_amd64_0d8d61270dfb4560\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130471.inf_amd64_26ad6921447aa568\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130624.inf_amd64_d85487143eec5e1a\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130825.inf_amd64_ee3ba427c553f15f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki130871.inf_amd64_382f7c369d4bf777\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131064.inf_amd64_5d13f27a9a9843fa\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131176.inf_amd64_fb4fe914575fdd15\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131191.inf_amd64_d668106cb6f2eae0\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki131622.inf_amd64_0058d71ace34db73\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132032.inf_amd64_f29660d80998e019\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132337.inf_amd64_223d6831ffa64ab1\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132535.inf_amd64_7875dff189ab2fa2\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132544.inf_amd64_b8c1f31373153db4\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132574.inf_amd64_54c9b905b975ee55\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132869.inf_amd64_052eb72d070df60f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\kit126731.inf_amd64_1905c9d5f38631d9\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
|
||||
dnscmd.exe,c:\windows\system32\*,A command-line interface for managing DNS servers
|
||||
dnscmd.exe,c:\windows\syswow64\*,A command-line interface for managing DNS servers
|
||||
wab.exe,c:\program files\windows mail\*,Windows address book manager
|
||||
wab.exe,c:\program files (x86)\windows mail\*,Windows address book manager
|
||||
msconfig.exe,c:\windows\system32\*,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows"
|
||||
wscript.exe,c:\windows\system32\*,Used by Windows to execute scripts
|
||||
wscript.exe,c:\windows\syswow64\*,Used by Windows to execute scripts
|
||||
makecab.exe,c:\windows\system32\*,Binary to package existing files into a cabinet (.cab) file
|
||||
makecab.exe,c:\windows\syswow64\*,Binary to package existing files into a cabinet (.cab) file
|
||||
datasvcutil.exe,c:\windows\microsoft.net\framework64\v3.5\*,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
|
||||
cmdl32.exe,c:\windows\system32\*,Microsoft Connection Manager Auto-Download
|
||||
cmdl32.exe,c:\windows\syswow64\*,Microsoft Connection Manager Auto-Download
|
||||
mshta.exe,c:\windows\system32\*,Used by Windows to execute html applications. (.hta)
|
||||
mshta.exe,c:\windows\syswow64\*,Used by Windows to execute html applications. (.hta)
|
||||
cmdkey.exe,c:\windows\system32\*,"creates, lists, and deletes stored user names and passwords or credentials."
|
||||
cmdkey.exe,c:\windows\syswow64\*,"creates, lists, and deletes stored user names and passwords or credentials."
|
||||
ilasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,used for compile c# code into dll or exe.
|
||||
ilasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,used for compile c# code into dll or exe.
|
||||
rdrleakdiag.exe,c:\windows\system32\*,Microsoft Windows resource leak diagnostic tool
|
||||
rdrleakdiag.exe,c:\windows\syswow64\*,Microsoft Windows resource leak diagnostic tool
|
||||
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.4-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
|
||||
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.7-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
|
||||
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
|
||||
jsc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
|
||||
jsc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
|
||||
jsc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
|
||||
jsc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
|
||||
cmstp.exe,c:\windows\system32\*,Installs or removes a Connection Manager service profile.
|
||||
cmstp.exe,c:\windows\syswow64\*,Installs or removes a Connection Manager service profile.
|
||||
stordiag.exe,c:\windows\system32\*,Storage diagnostic tool
|
||||
stordiag.exe,c:\windows\syswow64\*,Storage diagnostic tool
|
||||
odbcconf.exe,c:\windows\system32\*,Used in Windows for managing ODBC connections
|
||||
odbcconf.exe,c:\windows\syswow64\*,Used in Windows for managing ODBC connections
|
||||
wlrmdr.exe,c:\windows\system32\*,Windows Logon Reminder executable
|
||||
printbrm.exe,c:\windows\system32\spool\tools\*,Printer Migration Command-Line Tool
|
||||
dfsvc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
|
||||
dfsvc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
|
||||
dfsvc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
|
||||
dfsvc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
|
||||
extrac32.exe,c:\windows\system32\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
|
||||
extrac32.exe,c:\windows\syswow64\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
|
||||
rundll32.exe,c:\windows\system32\*,Used by Windows to execute dll files
|
||||
rundll32.exe,c:\windows\syswow64\*,Used by Windows to execute dll files
|
||||
runonce.exe,c:\windows\system32\*,Executes a Run Once Task that has been configured in the registry
|
||||
runonce.exe,c:\windows\syswow64\*,Executes a Run Once Task that has been configured in the registry
|
||||
explorer.exe,c:\windows\*,Binary used for managing files and system components within Windows
|
||||
explorer.exe,c:\windows\syswow64\*,Binary used for managing files and system components within Windows
|
||||
wuauclt.exe,c:\windows\system32\*,Windows Update Client
|
||||
wsreset.exe,c:\windows\system32\*,Used to reset Windows Store settings according to its manifest file
|
||||
finger.exe,c:\windows\system32\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
|
||||
finger.exe,c:\windows\syswow64\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
|
||||
regini.exe,c:\windows\system32\*,Used to manipulate the registry
|
||||
regini.exe,c:\windows\syswow64\*,Used to manipulate the registry
|
||||
reg.exe,c:\windows\system32\*,Used to manipulate the registry
|
||||
reg.exe,c:\windows\syswow64\*,Used to manipulate the registry
|
||||
syncappvpublishingserver.exe,c:\windows\system32\*,Used by App-v to get App-v server lists
|
||||
syncappvpublishingserver.exe,c:\windows\syswow64\*,Used by App-v to get App-v server lists
|
||||
bitsadmin.exe,c:\windows\system32\*,Used for managing background intelligent transfer
|
||||
bitsadmin.exe,c:\windows\syswow64\*,Used for managing background intelligent transfer
|
||||
msiexec.exe,c:\windows\system32\*,Used by Windows to execute msi files
|
||||
msiexec.exe,c:\windows\syswow64\*,Used by Windows to execute msi files
|
||||
regsvcs.exe,c:\windows\system32\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
|
||||
regsvcs.exe,c:\windows\syswow64\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
|
||||
gpscript.exe,c:\windows\system32\*,Used by group policy to process scripts
|
||||
gpscript.exe,c:\windows\syswow64\*,Used by group policy to process scripts
|
||||
diskshadow.exe,c:\windows\system32\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
|
||||
diskshadow.exe,c:\windows\syswow64\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
|
||||
ieexec.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
|
||||
ieexec.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
|
||||
diantz.exe,c:\windows\system32\*,Binary that package existing files into a cabinet (.cab) file
|
||||
diantz.exe,c:\windows\syswow64\*,Binary that package existing files into a cabinet (.cab) file
|
||||
desktopimgdownldr.exe,c:\windows\system32\*,Windows binary used to configure lockscreen/desktop image
|
||||
appinstaller.exe,c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\*,Tool used for installation of AppX/MSIX applications on Windows 10
|
||||
sc.exe,c:\windows\system32\*,Used by Windows to manage services
|
||||
sc.exe,c:\windows\syswow64\*,Used by Windows to manage services
|
||||
replace.exe,c:\windows\system32\*,Used to replace file with another file
|
||||
replace.exe,c:\windows\syswow64\*,Used to replace file with another file
|
||||
schtasks.exe,c:\windows\system32\*,Schedule periodic tasks
|
||||
schtasks.exe,c:\windows\syswow64\*,Schedule periodic tasks
|
||||
microsoft.workflow.compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,A utility included with .NET that is capable of compiling and executing C# or VB.net code.
|
||||
expand.exe,c:\windows\system32\*,Binary that expands one or more compressed files
|
||||
expand.exe,c:\windows\syswow64\*,Binary that expands one or more compressed files
|
||||
conhost.exe,c:\windows\system32\*,Console Window host
|
||||
bash.exe,c:\windows\system32\*,File used by Windows subsystem for Linux
|
||||
bash.exe,c:\windows\syswow64\*,File used by Windows subsystem for Linux
|
||||
pcwrun.exe,c:\windows\system32\*,Program Compatibility Wizard
|
||||
fltmc.exe,c:\windows\system32\*,Filter Manager Control Program used by Windows
|
||||
wmic.exe,c:\windows\system32\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
|
||||
wmic.exe,c:\windows\syswow64\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
|
||||
workfolders.exe,c:\windows\system32\*,Work Folders
|
||||
settingsynchost.exe,c:\windows\system32\*,Host Process for Setting Synchronization
|
||||
settingsynchost.exe,c:\windows\syswow64\*,Host Process for Setting Synchronization
|
||||
pktmon.exe,c:\windows\system32\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
|
||||
pktmon.exe,c:\windows\syswow64\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
|
||||
aspnet_compiler.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ASP.NET Compilation Tool
|
||||
aspnet_compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ASP.NET Compilation Tool
|
||||
cscript.exe,c:\windows\system32\*,Binary used to execute scripts in Windows
|
||||
cscript.exe,c:\windows\syswow64\*,Binary used to execute scripts in Windows
|
||||
installutil.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
|
||||
installutil.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
|
||||
installutil.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
|
||||
installutil.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
|
||||
esentutl.exe,c:\windows\system32\*,Binary for working with Microsoft Joint Engine Technology (JET) database
|
||||
esentutl.exe,c:\windows\syswow64\*,Binary for working with Microsoft Joint Engine Technology (JET) database
|
||||
hh.exe,c:\windows\*,Binary used for processing chm files in Windows
|
||||
hh.exe,c:\windows\syswow64\*,Binary used for processing chm files in Windows
|
||||
findstr.exe,c:\windows\system32\*,"Write to ADS, discover, or download files with Findstr.exe"
|
||||
findstr.exe,c:\windows\syswow64\*,"Write to ADS, discover, or download files with Findstr.exe"
|
||||
verclsid.exe,c:\windows\system32\*,Used to verify a COM object before it is instantiated by Windows Explorer
|
||||
verclsid.exe,c:\windows\syswow64\*,Used to verify a COM object before it is instantiated by Windows Explorer
|
||||
certreq.exe,c:\windows\system32\*,Used for requesting and managing certificates
|
||||
certreq.exe,c:\windows\syswow64\*,Used for requesting and managing certificates
|
||||
csc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile C# code
|
||||
csc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile C# code
|
||||
imewdbld.exe,c:\windows\system32\ime\shared\*,Microsoft IME Open Extended Dictionary Module
|
||||
presentationhost.exe,c:\windows\system32\*,File is used for executing Browser applications
|
||||
presentationhost.exe,c:\windows\syswow64\*,File is used for executing Browser applications
|
||||
shell32.dll,c:\windows\system32\*,Windows Shell Common Dll
|
||||
shell32.dll,c:\windows\syswow64\*,Windows Shell Common Dll
|
||||
zipfldr.dll,c:\windows\system32\*,Compressed Folder library
|
||||
zipfldr.dll,c:\windows\syswow64\*,Compressed Folder library
|
||||
desk.cpl,c:\windows\system32\*,Desktop Settings Control Panel
|
||||
desk.cpl,c:\windows\syswow64\*,Desktop Settings Control Panel
|
||||
comsvcs.dll,c:\windows\system32\*,COM+ Services
|
||||
setupapi.dll,c:\windows\system32\*,Windows Setup Application Programming Interface
|
||||
setupapi.dll,c:\windows\syswow64\*,Windows Setup Application Programming Interface
|
||||
mshtml.dll,c:\windows\system32\*,Microsoft HTML Viewer
|
||||
mshtml.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
|
||||
advpack.dll,c:\windows\system32\*,Utility for installing software and drivers with rundll32.exe
|
||||
advpack.dll,c:\windows\syswow64\*,Utility for installing software and drivers with rundll32.exe
|
||||
pcwutl.dll,c:\windows\system32\*,Microsoft HTML Viewer
|
||||
pcwutl.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
|
||||
shdocvw.dll,c:\windows\system32\*,Shell Doc Object and Control Library.
|
||||
shdocvw.dll,c:\windows\syswow64\*,Shell Doc Object and Control Library.
|
||||
ieframe.dll,c:\windows\system32\*,Internet Browser DLL for translating HTML code.
|
||||
ieframe.dll,c:\windows\syswow64\*,Internet Browser DLL for translating HTML code.
|
||||
dfshim.dll,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
|
||||
dfshim.dll,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
|
||||
dfshim.dll,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
|
||||
dfshim.dll,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
|
||||
url.dll,c:\windows\system32\*,Internet Shortcut Shell Extension DLL.
|
||||
url.dll,c:\windows\syswow64\*,Internet Shortcut Shell Extension DLL.
|
||||
ieadvpack.dll,c:\windows\system32\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
|
||||
ieadvpack.dll,c:\windows\syswow64\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
|
||||
syssetup.dll,c:\windows\system32\*,Windows NT System Setup
|
||||
syssetup.dll,c:\windows\syswow64\*,Windows NT System Setup
|
||||
winrm.vbs,c:\windows\system32\*,Script used for manage Windows RM settings
|
||||
winrm.vbs,c:\windows\syswow64\*,Script used for manage Windows RM settings
|
||||
manage-bde.wsf,c:\windows\system32\*,Script for managing BitLocker
|
||||
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\windowsupdate\*,Proxy execution with CL_Mutexverifiers.ps1
|
||||
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\audio\*,Proxy execution with CL_Mutexverifiers.ps1
|
||||
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\video\*,Proxy execution with CL_Mutexverifiers.ps1
|
||||
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\speech\*,Proxy execution with CL_Mutexverifiers.ps1
|
||||
pubprn.vbs,c:\windows\system32\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs
|
||||
pubprn.vbs,c:\windows\syswow64\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs
|
||||
pester.bat,c:\program files\windowspowershell\modules\pester\3.4.0\bin\*,Used as part of the Powershell pester
|
||||
pester.bat,c:\program files\windowspowershell\modules\pester\*\bin\*,Used as part of the Powershell pester
|
||||
cl_loadassembly.ps1,c:\windows\diagnostics\system\audio\*,PowerShell Diagnostic Script
|
||||
syncappvpublishingserver.vbs,c:\windows\system32\*,Script used related to app-v and publishing server
|
||||
cl_invocation.ps1,c:\windows\diagnostics\system\aero\*,Aero diagnostics script
|
||||
cl_invocation.ps1,c:\windows\diagnostics\system\audio\*,Aero diagnostics script
|
||||
cl_invocation.ps1,c:\windows\diagnostics\system\windowsupdate\*,Aero diagnostics script
|
||||
utilityfunctions.ps1,c:\windows\diagnostics\system\networking\*,PowerShell Diagnostic Script
|
||||
coregen.exe,c:\program files\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
|
||||
coregen.exe,c:\program files (x86)\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
|
||||
fsi.exe,c:\program files\dotnet\sdk\[sdk version]\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
|
||||
fsi.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
|
||||
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\arm64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
|
||||
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\x64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
|
||||
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
|
||||
ntdsutil.exe,c:\windows\system32\*,Command line utility used to export Active Directory.
|
||||
sqltoolsps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
|
||||
dump64.exe,c:\program files (x86)\microsoft visual studio\installer\feedback\*,Memory dump tool that comes with Microsoft Visual Studio
|
||||
wsl.exe,c:\windows\system32\*,Windows subsystem for Linux executable
|
||||
csi.exe,c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\*,Command line interface included with Visual Studio.
|
||||
csi.exe,c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\*,Command line interface included with Visual Studio.
|
||||
mftrace.exe,c:\program files (x86)\windows kits\10\bin\10.0.16299.0\*,Trace log generation tool for Media Foundation Tools.
|
||||
mftrace.exe,c:\program files (x86)\windows kits\10\bin\*,Trace log generation tool for Media Foundation Tools.
|
||||
adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
|
||||
adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
|
||||
excel.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary
|
||||
excel.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary
|
||||
excel.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary
|
||||
excel.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary
|
||||
excel.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary
|
||||
excel.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary
|
||||
excel.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary
|
||||
excel.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary
|
||||
dotnet.exe,c:\program files\dotnet\*,dotnet.exe comes with .NET Framework
|
||||
sqlps.exe,c:\program files (x86)\microsoft sql server\100\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
|
||||
sqlps.exe,c:\program files (x86)\microsoft sql server\110\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
|
||||
sqlps.exe,c:\program files (x86)\microsoft sql server\120\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
|
||||
sqlps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
|
||||
sqlps.exe,c:\program files (x86)\microsoft sql server\150\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
|
||||
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\*,Verifies UI accessibility requirements
|
||||
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\*,Verifies UI accessibility requirements
|
||||
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\*,Verifies UI accessibility requirements
|
||||
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\*,Verifies UI accessibility requirements
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary.
|
||||
powerpnt.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary.
|
||||
sqldumper.exe,c:\program files\microsoft sql server\90\shared\*,Debugging utility included with Microsoft SQL.
|
||||
sqldumper.exe,c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\*,Debugging utility included with Microsoft SQL.
|
||||
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
|
||||
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
|
||||
appvlp.exe,c:\program files\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
|
||||
appvlp.exe,c:\program files (x86)\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
|
||||
agentexecutor.exe,c:\program files (x86)\*,Intune Management Extension included on Intune Managed Devices
|
||||
dxcap.exe,c:\windows\system32\*,DirectX diagnostics/debugger included with Visual Studio.
|
||||
dxcap.exe,c:\windows\syswow64\*,DirectX diagnostics/debugger included with Visual Studio.
|
||||
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools.
|
||||
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools.
|
||||
defaultpack.exe,c:\program files (x86)\microsoft\defaultpack\*,This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
|
||||
devtoolslauncher.exe,c:\windows\system32\*,Binary will execute specified binary. Part of VS/VScode installation.
|
||||
vsiisexelauncher.exe,c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\*,Binary will execute specified binary. Part of VS/VScode installation.
|
||||
winword.exe,c:\program files\microsoft office\root\office16\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary
|
||||
winword.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary
|
||||
winword.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary
|
||||
fsianycpu.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,32/64-bit FSharp (F#) Interpreter included with Visual Studio.
|
||||
vsjitdebugger.exe,c:\windows\system32\*,Just-In-Time (JIT) debugger included with Visual Studio
|
||||
wfc.exe,c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\*,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
|
||||
msdeploy.exe,c:\program files (x86)\iis\microsoft web deploy v3\*,Microsoft tool used to deploy Web Applications.
|
||||
|
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user