Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new rules for detection msdt.exe create file to autorun #3430

Merged
merged 5 commits into from
Aug 26, 2022

Conversation

d3f0x0
Copy link
Contributor

@d3f0x0 d3f0x0 commented Aug 24, 2022

detecting the creation of a file in the startup folder by the process msdt.exe

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Aug 25, 2022

This rule has several issues that'll show up, once I approve and run the workflow.

It's detection idea is good, but it's too specific. There are many more folders in which a file creation by msdt.exe could be suspicious.

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Aug 25, 2022

I've fixed the issues with the rule myself

@d3f0x0
Copy link
Contributor Author

d3f0x0 commented Aug 25, 2022

@Neo23x0 Do I need to do something?

@Neo23x0 Neo23x0 merged commit 112d83f into SigmaHQ:master Aug 26, 2022
@Neo23x0
Copy link
Collaborator

Neo23x0 commented Aug 26, 2022

No, just wait until the tests are completed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants