Update C2-NamedPipe.md
This commit is contained in:
Родитель
ad82f13fe6
Коммит
19253acb9f
|
@ -82,7 +82,7 @@ This query can be used to detect the following attack techniques and tactics ([s
|
|||
|
||||
**Contributor:** [@xknow_infosec](https://twitter.com/xknow_infosec)
|
||||
|
||||
This detection is a summary of knowledge already known. Credits only to original authors. Defender for Endpoint lately just added a new ActionType for SMB named pipes (NamedPipeEvent), which would allow equal usecase now based on the same telemetry (for example Sysmon EventID 17/18).
|
||||
This detection is a summary of knowledge already known. Credits only to original authors. Defender for Endpoint lately just added a new ActionType for SMB named pipes (NamedPipeEvent), which would allow new equal usecases now based on the same telemetry (for example replicating all Sysmon EventID 17/18 detections).
|
||||
|
||||
Original Authors / Credits / Ressources:
|
||||
* https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/sysmon_psexec_pipes_artifacts.yml
|
||||
|
|
Загрузка…
Ссылка в новой задаче