Files
splunk-security_content/lookups/hijacklibs.yml
2025-03-26 11:01:05 -05:00

11 lines
277 B
YAML

name: hijacklibs
date: 2024-12-23
version: 2
id: 00990d97-e923-4ae7-9fa0-b5033a8b0164
author: Splunk Threat Research Team
lookup_type: csv
description: A list of potentially abused libraries in Windows
match_type:
- WILDCARD(library)
min_matches: 1
case_sensitive_match: false