Skip to content

Conversation

@ssi0202
Copy link

@ssi0202 ssi0202 commented Jun 1, 2018

initial compromise via browser (drive by)

spearphising (office suite launches cmd powershell etc.)

tested with embeded code in office documents to launch browser and cmd/powershell

you will need to do a bit of tuning in your sysmon config to get rid of noise from onedrive / groove.exe

@neu5ron
Copy link
Collaborator

neu5ron commented Feb 22, 2019

@ssi0202 can you make sigma rules for these perhaps? this might be a great use case

@ssi0202
Copy link
Author

ssi0202 commented Mar 2, 2019

im lookin into the sigma stuff

this presentation from SANS is really good by the way
https://www.youtube.com/watch?v=PdCQChYrxXg

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants