Skip to content

Commit 29c61dc

Browse files
committed
new ADS stream creation expressions
1 parent d852990 commit 29c61dc

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

sysmonconfig-export.xml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -892,6 +892,9 @@
892892
<TargetFilename condition="end with">.vb</TargetFilename> <!--VisualBasicScripting files-->
893893
<TargetFilename condition="end with">.vbe</TargetFilename> <!--VisualBasicScripting files-->
894894
<TargetFilename condition="end with">.vbs</TargetFilename> <!--VisualBasicScripting files-->
895+
<TargetFilename condition="end with">:Zone.Identifier</TargetFilename> <!-- Track Zone.Identifiers regardless of their download location -->
896+
<TargetFilename condition="end with">:newads</TargetFilename> <!-- CobaltStrike BOF https://github.com/EspressoCake/Self_Deletion_BOF/blob/main/src/main.c -->
897+
895898
</FileCreateStreamHash>
896899

897900
<RuleGroup name="" groupRelation="or">

0 commit comments

Comments
 (0)