mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
accidental story
This commit is contained in:
@@ -1,22 +0,0 @@
|
||||
author: Michael Haag, Splunk
|
||||
date: '2021-02-11'
|
||||
description: Monitor and detect techniques used by attackers who leverage the mshta.exe
|
||||
process to execute malicious code.
|
||||
id: 2cdf33a0-4805-4b61-b025-59c20f418fbe
|
||||
name: Suspicious Regsvcs Regasm Activity
|
||||
narrative: ' Not done yet '
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/009/
|
||||
- https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/evasion/windows/applocker_evasion_regasm_regsvcs.md
|
||||
- https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/
|
||||
tags:
|
||||
analytic_story: Suspicious Regsvcs Regasm Activity
|
||||
category:
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
type: ESCU
|
||||
version: 1
|
||||
Reference in New Issue
Block a user