Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable automatic windows defragementation rule #70

Closed
sfakiana opened this issue Mar 10, 2018 · 5 comments
Closed

Disable automatic windows defragementation rule #70

sfakiana opened this issue Mar 10, 2018 · 5 comments

Comments

@sfakiana
Copy link

It would be nice to create a sigma rule to monitor disabling of windows automatic defragmentation
https://securelist.com/apt-slingshot/84312/

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Mar 10, 2018

@sfakiana
Copy link
Author

!!! That was really quick Florian :)
what about the scheduled task via Sysmon EventID1?
schtasks /Delete /TN "\Microsoft\Windows\Defrag\ScheduledDefrag" /F
https://superuser.com/questions/1210453/windows-10-disable-automatic-defragmentation

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Mar 10, 2018

Check 74c2f91?diff=split

@sfakiana
Copy link
Author

good stuff Florian! I think it's fine. Many thanks!

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Mar 10, 2018

👍

@Neo23x0 Neo23x0 closed this as completed Mar 10, 2018
thomaspatzke added a commit that referenced this issue Oct 12, 2020
[OSCD] Detecting Code injection with PowerShell in another process #70
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants