Skip to content

Commit c327298

Browse files
authored
Merge pull request #18 from Neo23x0/config-devel
New FileStream rules
2 parents 0676604 + 0ea30fe commit c327298

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

sysmonconfig-export.xml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -892,6 +892,9 @@
892892
<TargetFilename condition="end with">.vb</TargetFilename> <!--VisualBasicScripting files-->
893893
<TargetFilename condition="end with">.vbe</TargetFilename> <!--VisualBasicScripting files-->
894894
<TargetFilename condition="end with">.vbs</TargetFilename> <!--VisualBasicScripting files-->
895+
<TargetFilename condition="end with">:Zone.Identifier</TargetFilename> <!-- Track Zone.Identifiers regardless of their download location -->
896+
<TargetFilename condition="end with">:newads</TargetFilename> <!-- CobaltStrike BOF https://github.com/EspressoCake/Self_Deletion_BOF/blob/main/src/main.c -->
897+
895898
</FileCreateStreamHash>
896899

897900
<RuleGroup name="" groupRelation="or">

0 commit comments

Comments
 (0)