Haha this is awesome I’ve always wanted to see how you would chain together the weaker exclusions in the Sysmon config. Acrord32 was consolidation. OneDrive.exe is hard.
Want to ask @markrussinovich to allow exclusion rules for OriginalFileName of Microsoft-signed binaries
-
-
-
Thanks! I'm sure now you can see more clearly that this is all an inherent limitation of the rules engine (i.e. exclude rules based on attacker-influencible data sources) and not the robustness of your ruleset.


- Još 3 druga odgovora
Novi razgovor -
-
-
One of the evasion techniques discussed was the fact that any existing class can be cloned in any arbitrary namespace rendering namespace-based detections ineffective.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
And yes, buying ads counts...
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.