accidental story

This commit is contained in:
mhaag-spl
2021-02-12 12:12:37 -07:00
parent fd3910ae5b
commit 970d7e9031
@@ -1,22 +0,0 @@
author: Michael Haag, Splunk
date: '2021-02-11'
description: Monitor and detect techniques used by attackers who leverage the mshta.exe
process to execute malicious code.
id: 2cdf33a0-4805-4b61-b025-59c20f418fbe
name: Suspicious Regsvcs Regasm Activity
narrative: ' Not done yet '
references:
- https://attack.mitre.org/techniques/T1218/009/
- https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/evasion/windows/applocker_evasion_regasm_regsvcs.md
- https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/
tags:
analytic_story: Suspicious Regsvcs Regasm Activity
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
type: ESCU
version: 1