Skip to content

Commit d852990

Browse files
committed
Winword writes .cab / .inf files : CVE-2021-40444 detection
1 parent a1e9a8f commit d852990

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

sysmonconfig-export.xml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -587,6 +587,10 @@
587587
<TargetFilename condition="contains">\hive_sam_</TargetFilename> <!-- Default output of HiveNightmare / SeriousSAM tools -->
588588
<TargetFilename condition="is">C:\windows\temp\sam</TargetFilename> <!-- Default output of HiveNightmare / SeriousSAM tools -->
589589
<TargetFilename condition="begin with">C:\Windows\System32\spool\drivers\x64</TargetFilename> <!-- PrinterNight -->
590+
<Rule groupRelation="and"> <!-- CVE-2021-40444 https://twitter.com/RonnyTNL/status/1436334640617373699 -->
591+
<Image condition="end with">\WINWORD.EXE</Image>
592+
<TargetFilename condition="contains any">.cab;.inf</TargetFilename>
593+
</Rule>
590594
</FileCreate>
591595
</RuleGroup>
592596

0 commit comments

Comments
 (0)