Skip to content

Conversation

@kevinelwell
Copy link

Created issue 48

Change line 239 from:
<TargetObject condition="is">\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Print to PDF\PrinterDriverData</TargetObject>

to:
<TargetObject condition="is">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Print to PDF\PrinterDriverData</TargetObject>

Neo23x0 and others added 30 commits July 24, 2021 08:22
This was necessary to allow us to 1. merge all open pull request of the original repo AND 2. allow our new repository to receive new pull requests
Added a workflow that installs sysmon with the config and fails when sysmon has an error
Also changed the numbers to allow up to about 5% of more events
Process Access Config für lsass.exe and CobaltStrike BOF
New CobaltStrike NamedPipes
Neo23x0 and others added 30 commits June 28, 2023 19:21
feat: add vmware conf path
adding EDRSandblast itself (not just the drivers used by it)
Add Defender administrative settings related another registry path
add new pipes

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
…filefix attacks (#63)

add RunMRU annd TypedPaths Registry to detect potential clickfix and filefix attacks

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
DNS ServerLevelPluginDll Issue Added
(cherry picked from commit c612d4239156f052a67ef7d2a740d1079013726c)
Add registry keys often used by malware and windows services
(cherry picked from commit b06840bf9cbe5903f6bdfe5b80366b0f2405dd0c)
Remove noise network profile switches
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.