Skip to content

Commit ea785bc

Browse files
authored
Merge pull request #13 from Neo23x0/config-devel
feat: efspotato named pipe
2 parents 289d5e9 + 254932d commit ea785bc

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

sysmonconfig-export.xml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -918,6 +918,7 @@
918918
<!-- Malware -->
919919
<PipeName condition="contains any">\isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc</PipeName>
920920
<PipeName condition="contains any">\atctl;\userpipe;\iehelper;\sdlrpc;\comnap</PipeName>
921+
<PipeName condition="contains">\pipe\</PipeName> <!-- EfsPotato https://twitter.com/SBousseaden/status/1429530155291193354?s=20 -->
921922
<!-- Cobalt Strike Pipe Names -->
922923
<PipeName condition="contains all">MSSE-;-server</PipeName>
923924
<PipeName condition="begin with">\postex_</PipeName>

0 commit comments

Comments
 (0)