We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 5c2fdc2 commit d3dbaddCopy full SHA for d3dbadd
1 file changed
sysmonconfig-export.xml
@@ -958,6 +958,7 @@
958
<PipeName condition="begin with">\wkssvc</PipeName>
959
<!-- Other specific named pipes -->
960
<PipeName condition="contains">6e7645c4-32c5-4fe3-aabf-e94c2f4370e7</PipeName> <!-- LiquidSnake hacktool https://github.com/RiccardoAncarani/LiquidSnake -->
961
+ <Image condition="end with">\scrcons.exe</Image> <!-- Susupicious WMI Event Consumer creating a named pipe -->
962
</PipeEvent>
963
</RuleGroup>
964
<!-- we skip the connect pipe event since they could be to noisy and a CreatePipe event should come before these -->
0 commit comments