mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update windows_powershell_import_applocker_policy.yml
This commit is contained in:
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic is to identify a process that importing applocker xml rule using powershell commandlet.
|
||||
description: The following analytic is to identify a process that imports applocker xml rules using powershell commandlet.
|
||||
This technique was seen in Azorult malware where it drop an xml applocker rules that will deny several AV product and then executed using powershell aplocker
|
||||
commandlet. This event is really suspicious and need to be check that may lead for further IOC that tries to evade detections, persistence or even
|
||||
privilege escalation.
|
||||
|
||||
Reference in New Issue
Block a user