Skip to content

Commit d8da168

Browse files
author
Azure Pipeline
committed
Updated after successful CICD run 02/07/2022 17:54:40 UTC
1 parent b1ef9ba commit d8da168

File tree

2 files changed

+8
-0
lines changed

2 files changed

+8
-0
lines changed

Diff for: 0_custom_configuration/all_modules.txt

66 Bytes
Binary file not shown.

Diff for: sysmonconfig.xml

+8
Original file line numberDiff line numberDiff line change
@@ -1307,6 +1307,14 @@
13071307
<TargetFilename condition="end with">.vb</TargetFilename>
13081308
<TargetFilename condition="end with">.vbe</TargetFilename>
13091309
<TargetFilename condition="end with">.vbs</TargetFilename>
1310+
<Rule groupRelation="and">
1311+
<TargetFilename name="technique_id=T1562.001,technique_name=Disable or Modify tools" condition="begin with">C:\Windows\System32\CodeIntegrity\CIPolicies\Active\</TargetFilename>
1312+
<TargetFilename name="technique_id=T1562.001,technique_name=Disable or Modify tools" condition="end with">.cip</TargetFilename>
1313+
</Rule>
1314+
<Rule groupRelation="and">
1315+
<TargetFilename name="technique_id=T1562.001,technique_name=Disable or Modify tools" condition="begin with">C:\Windows\System32\CodeIntegrity\</TargetFilename>
1316+
<TargetFilename name="technique_id=T1562.001,technique_name=Disable or Modify tools" condition="end with">.p7b</TargetFilename>
1317+
</Rule>
13101318
<TargetFilename name="technique_id=T1047,technique_name=Windows Management Instrumentation" condition="begin with">C:\Windows\System32\Wbem</TargetFilename>
13111319
<TargetFilename name="technique_id=T1047,technique_name=Windows Management Instrumentation" condition="begin with">C:\Windows\SysWOW64\Wbem</TargetFilename>
13121320
<Image name="technique_id=T1047,technique_name=Windows Management Instrumentation" condition="begin with">C:\WINDOWS\system32\wbem\scrcons.exe</Image>

0 commit comments

Comments
 (0)