We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 9af65f5 commit 40bdcfcCopy full SHA for 40bdcfc
1 file changed
sysmonconfig-export.xml
@@ -492,6 +492,11 @@
492
<CallTrace condition="not begin with">C:\Windows\SYSTEM32\wow64win.dll</CallTrace>
493
</Rule>
494
<CallTrace condition="begin with">UNKNOWN</CallTrace>
495
+ <!-- Inject AMSI Bypass via CobaltStrike BOF Ref: https://github.com/boku7/injectAmsiBypass -->
496
+ <Rule groupRelation="and">
497
+ <CallTrace condition="contains">UNKNOWN</CallTrace>
498
+ <GrantedAccess condition="contains any">0x1028</GrantedAccess>
499
+ </Rule>
500
<!-- lsass.exe access with critical permission -->
501
<Rule groupRelation="and">
502
<TargetImage condition="end with">lsass.exe</TargetImage>
0 commit comments