Skip to content

Conversation

@kevinelwell
Copy link

Created issue 48

Change line 239 from:
<TargetObject condition="is">\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Print to PDF\PrinterDriverData</TargetObject>

to:
<TargetObject condition="is">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Print to PDF\PrinterDriverData</TargetObject>

Neo23x0 and others added 30 commits July 24, 2021 08:22
This was necessary to allow us to 1. merge all open pull request of the original repo AND 2. allow our new repository to receive new pull requests
Added a workflow that installs sysmon with the config and fails when sysmon has an error
Also changed the numbers to allow up to about 5% of more events
Process Access Config für lsass.exe and CobaltStrike BOF
New CobaltStrike NamedPipes
cospirho and others added 30 commits May 15, 2023 13:49
feat: remove duplicate rules
feat: add vmware conf path
adding EDRSandblast itself (not just the drivers used by it)
Add Defender administrative settings related another registry path
add new pipes

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
…filefix attacks (#63)

add RunMRU annd TypedPaths Registry to detect potential clickfix and filefix attacks

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
DNS ServerLevelPluginDll Issue Added
(cherry picked from commit c612d4239156f052a67ef7d2a740d1079013726c)
Add registry keys often used by malware and windows services
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.