Merge branch 'qakbot_2' of github.com:splunk/security_content into qakbot_2

This commit is contained in:
tccontre
2022-10-24 15:14:58 +02:00
@@ -35,7 +35,7 @@ tags:
impact: 90
kill_chain_phases:
- Exploitation
message:
message: a dll modules is loaded by calc.exe in $ImageLoaded$ that are not in common windows OS installation folder in $Computer$
mitre_attack_id:
- T1574.002
- T1574
@@ -61,4 +61,4 @@ tags:
- ProcessId
risk_score: 90
security_domain: endpoint
asset_type: Endpoint
asset_type: Endpoint