Skip to content

Commit 86397d2

Browse files
committed
generalise CobaltStrike BOF ProcessAccess Pattern
1 parent be79a15 commit 86397d2

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

sysmonconfig-export.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -487,10 +487,10 @@
487487
<ProcessAccess onmatch="include">
488488
<!-- CobaltStrike BOF using OpenProcess/NtOpenProcess Ref: https://medium.com/falconforce/falconfriday-direct-system-calls-and-cobalt-strike-bofs-0xff14-741fa8e1bdd6 -->
489489
<CallTrace condition="begin with">UNKNOWN</CallTrace>
490-
<!-- Inject AMSI Bypass via CobaltStrike BOF Ref: https://github.com/boku7/injectAmsiBypass -->
490+
<!-- Typical ProcessAccess Pattern of CobaltStrike BOF Ref: e.g. https://github.com/boku7/injectAmsiBypass -->
491491
<Rule groupRelation="and">
492492
<CallTrace condition="contains">UNKNOWN</CallTrace>
493-
<GrantedAccess condition="contains any">0x1028</GrantedAccess>
493+
<GrantedAccess condition="contains any">0x1028;0x1fffff</GrantedAccess>
494494
</Rule>
495495
<!-- lsass.exe access with critical permission -->
496496
<Rule groupRelation="and">

0 commit comments

Comments
 (0)