Update windows_powershell_import_applocker_policy.yml

This commit is contained in:
tccontre
2022-07-11 11:55:12 +02:00
committed by GitHub
parent e5d2e9f6f3
commit 74ea79b419
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic is to identify a process that importing applocker xml rule using powershell commandlet.
description: The following analytic is to identify a process that imports applocker xml rules using powershell commandlet.
This technique was seen in Azorult malware where it drop an xml applocker rules that will deny several AV product and then executed using powershell aplocker
commandlet. This event is really suspicious and need to be check that may lead for further IOC that tries to evade detections, persistence or even
privilege escalation.