|
26 | 26 | <ClInclude Include="headers\hunt\HuntRegister.h" /> |
27 | 27 | <ClInclude Include="headers\hunt\hunts\HuntT1004.h" /> |
28 | 28 | <ClInclude Include="headers\hunt\hunts\HuntT1015.h" /> |
| 29 | + <ClInclude Include="headers\hunt\hunts\HuntT1035.h" /> |
29 | 30 | <ClInclude Include="headers\hunt\hunts\HuntT1037.h" /> |
30 | 31 | <ClInclude Include="headers\hunt\hunts\HuntT1050.h" /> |
| 32 | + <ClInclude Include="headers\hunt\hunts\HuntT1053.h" /> |
31 | 33 | <ClInclude Include="headers\hunt\hunts\HuntT1055.h" /> |
32 | 34 | <ClInclude Include="headers\hunt\hunts\HuntT1060.h" /> |
33 | 35 | <ClInclude Include="headers\hunt\hunts\HuntT1099.h" /> |
|
39 | 41 | <ClInclude Include="headers\hunt\hunts\HuntT1138.h" /> |
40 | 42 | <ClInclude Include="headers\hunt\hunts\HuntT1182.h" /> |
41 | 43 | <ClInclude Include="headers\hunt\hunts\HuntT1183.h" /> |
42 | | - <ClInclude Include="headers\hunt\reaction\RemoveValue.h" /> |
43 | | - <ClInclude Include="headers\hunt\reaction\SuspendProcess.h" /> |
| 44 | + <ClInclude Include="headers\mitigation\mitigations\MitigateV71769.h" /> |
| 45 | + <ClInclude Include="headers\reaction\CarveMemory.h" /> |
| 46 | + <ClInclude Include="headers\reaction\RemoveValue.h" /> |
| 47 | + <ClInclude Include="headers\reaction\SuspendProcess.h" /> |
44 | 48 | <ClInclude Include="headers\hunt\RegistryHunt.h" /> |
45 | 49 | <ClInclude Include="headers\hunt\Scope.h" /> |
46 | 50 | <ClInclude Include="headers\mitigation\Mitigation.h" /> |
|
58 | 62 | <ClInclude Include="headers\mitigation\mitigations\MitigateV3340.h" /> |
59 | 63 | <ClInclude Include="headers\mitigation\mitigations\MitigateV3344.h" /> |
60 | 64 | <ClInclude Include="headers\mitigation\mitigations\MitigateV3379.h" /> |
| 65 | + <ClInclude Include="headers\mitigation\mitigations\MitigateV3479.h" /> |
61 | 66 | <ClInclude Include="headers\mitigation\mitigations\MitigateV63597.h" /> |
62 | 67 | <ClInclude Include="headers\mitigation\mitigations\MitigateV63687.h" /> |
63 | 68 | <ClInclude Include="headers\mitigation\mitigations\MitigateV63753.h" /> |
|
66 | 71 | <ClInclude Include="headers\mitigation\mitigations\MitigateV63829.h" /> |
67 | 72 | <ClInclude Include="headers\mitigation\mitigations\MitigateV72753.h" /> |
68 | 73 | <ClInclude Include="headers\mitigation\mitigations\MitigateV73519.h" /> |
| 74 | + <ClInclude Include="headers\mitigation\mitigations\MitigateV73585.h" /> |
69 | 75 | <ClInclude Include="headers\monitor\ETW_Wrapper.h"> |
70 | 76 | <ExcludedFromBuild Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">true</ExcludedFromBuild> |
71 | 77 | <ExcludedFromBuild Condition="'$(Configuration)|$(Platform)'=='Release|x64'">true</ExcludedFromBuild> |
|
135 | 141 | <ExcludedFromBuild Condition="'$(Configuration)|$(Platform)'=='Release|x64'">true</ExcludedFromBuild> |
136 | 142 | </ClInclude> |
137 | 143 | <ClInclude Include="headers\util\processes\Analyzer.h" /> |
138 | | - <ClInclude Include="headers\hunt\reaction\Detections.h" /> |
139 | | - <ClInclude Include="headers\hunt\reaction\Log.h" /> |
140 | | - <ClInclude Include="headers\hunt\reaction\Reaction.h" /> |
| 144 | + <ClInclude Include="headers\reaction\Detections.h" /> |
| 145 | + <ClInclude Include="headers\reaction\Log.h" /> |
| 146 | + <ClInclude Include="headers\reaction\Reaction.h" /> |
| 147 | + <ClInclude Include="headers\util\processes\PERemover.h" /> |
141 | 148 | <ClInclude Include="headers\util\processes\ProcessChecker.h" /> |
142 | 149 | <ClInclude Include="headers\util\processes\ProcessUtils.h" /> |
143 | 150 | </ItemGroup> |
|
147 | 154 | <ClCompile Include="src\hunt\HuntRegister.cpp" /> |
148 | 155 | <ClCompile Include="src\hunt\hunts\HuntT1004.cpp" /> |
149 | 156 | <ClCompile Include="src\hunt\hunts\HuntT1015.cpp" /> |
| 157 | + <ClCompile Include="src\hunt\hunts\HuntT1035.cpp" /> |
150 | 158 | <ClCompile Include="src\hunt\hunts\HuntT1037.cpp" /> |
151 | 159 | <ClCompile Include="src\hunt\hunts\HuntT1050.cpp" /> |
| 160 | + <ClCompile Include="src\hunt\hunts\HuntT1053.cpp" /> |
152 | 161 | <ClCompile Include="src\hunt\hunts\HuntT1055.cpp" /> |
153 | 162 | <ClCompile Include="src\hunt\hunts\HuntT1060.cpp" /> |
154 | 163 | <ClCompile Include="src\hunt\hunts\HuntT1099.cpp" /> |
|
160 | 169 | <ClCompile Include="src\hunt\hunts\HuntT1138.cpp" /> |
161 | 170 | <ClCompile Include="src\hunt\hunts\HuntT1182.cpp" /> |
162 | 171 | <ClCompile Include="src\hunt\hunts\HuntT1183.cpp" /> |
163 | | - <ClCompile Include="src\hunt\reaction\RemoveValue.cpp" /> |
164 | | - <ClCompile Include="src\hunt\reaction\SuspendProcess.cpp" /> |
| 172 | + <ClCompile Include="src\mitigation\mitigations\MitigateV71769.cpp" /> |
| 173 | + <ClCompile Include="src\reaction\CarveMemory.cpp" /> |
| 174 | + <ClCompile Include="src\reaction\RemoveValue.cpp" /> |
| 175 | + <ClCompile Include="src\reaction\SuspendProcess.cpp" /> |
165 | 176 | <ClCompile Include="src\hunt\RegistryHunt.cpp" /> |
166 | 177 | <ClCompile Include="src\hunt\Scope.cpp" /> |
167 | 178 | <ClCompile Include="src\mitigation\Mitigation.cpp" /> |
|
179 | 190 | <ClCompile Include="src\mitigation\mitigations\MitigateV3340.cpp" /> |
180 | 191 | <ClCompile Include="src\mitigation\mitigations\MitigateV3344.cpp" /> |
181 | 192 | <ClCompile Include="src\mitigation\mitigations\MitigateV3379.cpp" /> |
| 193 | + <ClCompile Include="src\mitigation\mitigations\MitigateV3479.cpp" /> |
182 | 194 | <ClCompile Include="src\mitigation\mitigations\MitigateV63597.cpp" /> |
183 | 195 | <ClCompile Include="src\mitigation\mitigations\MitigateV63687.cpp" /> |
184 | 196 | <ClCompile Include="src\mitigation\mitigations\MitigateV63753.cpp" /> |
|
187 | 199 | <ClCompile Include="src\mitigation\mitigations\MitigateV63829.cpp" /> |
188 | 200 | <ClCompile Include="src\mitigation\mitigations\MitigateV72753.cpp" /> |
189 | 201 | <ClCompile Include="src\mitigation\mitigations\MitigateV73519.cpp" /> |
| 202 | + <ClCompile Include="src\mitigation\mitigations\MitigateV73585.cpp" /> |
190 | 203 | <ClCompile Include="src\monitor\etw\ETW_Wrapper.cpp"> |
191 | 204 | <ExcludedFromBuild Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">true</ExcludedFromBuild> |
192 | 205 | <ExcludedFromBuild Condition="'$(Configuration)|$(Platform)'=='Release|x64'">true</ExcludedFromBuild> |
|
252 | 265 | <ExcludedFromBuild Condition="'$(Configuration)|$(Platform)'=='Release|x64'">true</ExcludedFromBuild> |
253 | 266 | </ClCompile> |
254 | 267 | <ClCompile Include="src\util\processes\Analyzer.cpp" /> |
255 | | - <ClCompile Include="src\hunt\reaction\ReactLog.cpp" /> |
256 | | - <ClCompile Include="src\hunt\reaction\Reaction.cpp" /> |
| 268 | + <ClCompile Include="src\reaction\ReactLog.cpp" /> |
| 269 | + <ClCompile Include="src\reaction\Reaction.cpp" /> |
| 270 | + <ClCompile Include="src\util\processes\PERemover.cpp" /> |
257 | 271 | <ClCompile Include="src\util\processes\ProcessUtils.cpp" /> |
258 | 272 | <ClInclude Include="resources\resource.h" /> |
259 | 273 | </ItemGroup> |
|
271 | 285 | <ItemGroup> |
272 | 286 | <None Include="resources\indicators" /> |
273 | 287 | <None Include="resources\severe" /> |
| 288 | + <None Include="resources\severe2" /> |
274 | 289 | </ItemGroup> |
275 | 290 | <ItemDefinitionGroup> |
276 | 291 | <BuildLog> |
277 | 292 | <Path>$(SolutionDir)build\$(PlatformTarget)\$(Configuration)\$(MSBuildProjectName).log</Path> |
278 | 293 | </BuildLog> |
279 | 294 | <ClCompile> |
280 | | - <AdditionalIncludeDirectories>$(SolutionDir)BLUESPAWN-client\external\pe-sieve\include;$(SolutionDir)BLUESPAWN-client\external\cxxopts\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories> |
| 295 | + <AdditionalIncludeDirectories>$(SolutionDir)BLUESPAWN-client\external\pe-sieve\libpeconv\libpeconv\include;$(SolutionDir)BLUESPAWN-client\external\pe-sieve\;$(SolutionDir)BLUESPAWN-client\external\pe-sieve\include;$(SolutionDir)BLUESPAWN-client\external\cxxopts\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories> |
281 | 296 | <RuntimeLibrary Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">MultiThreaded</RuntimeLibrary> |
282 | 297 | <RuntimeLibrary Condition="'$(Configuration)|$(Platform)'=='Release|x64'">MultiThreaded</RuntimeLibrary> |
283 | 298 | <RuntimeLibrary Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">MultiThreadedDebug</RuntimeLibrary> |
|
0 commit comments