mirror of
https://github.com/keyboardcrunch/SentinelOne-ATTACK-Queries
synced 2026-06-08 17:17:21 +00:00
Added T1546.007 netsh helper dll
This commit is contained in:
+10
@@ -109,3 +109,13 @@ Detects addition of logon scripts through command line or registry methods.
|
||||
```
|
||||
SrcProcCmdLine ContainsCIS "UserInitMprLogonScript" OR (RegistryKeyPath ContainsCIS "UserInitMprLogonScript" AND EventType = "Registry Value Create")
|
||||
```
|
||||
|
||||
### T1546.007 Netsh Helper DLL
|
||||
Atomics: [T1546.007]()
|
||||
|
||||
Detection of "helper" dlls with network command shell, through command arguments or registry modification.
|
||||
|
||||
```
|
||||
(TgtProcName = "netsh.exe" AND TgtProcCmdLine ContainsCIS "add helper") OR (RegistryPath ContainsCIS "SOFTWARE\Microsoft\NetSh" AND EventType = "Registry Value Create")
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user