Skip to content

Commit 290f0be

Browse files
authored
Update defense_evasion_execution_suspicious_explorer_winword.toml (#4533)
1 parent a64b6a3 commit 290f0be

File tree

1 file changed

+11
-10
lines changed

1 file changed

+11
-10
lines changed

rules/windows/defense_evasion_execution_suspicious_explorer_winword.toml

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
creation_date = "2020/09/03"
33
integration = ["endpoint", "windows", "m365_defender"]
44
maturity = "production"
5-
updated_date = "2025/01/15"
5+
updated_date = "2025/03/12"
66
min_stack_version = "8.14.0"
77
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

@@ -46,15 +46,16 @@ type = "eql"
4646

4747
query = '''
4848
process where host.os.type == "windows" and event.type == "start" and
49-
process.pe.original_file_name in ("WinWord.exe", "EXPLORER.EXE", "w3wp.exe", "DISM.EXE") and
50-
not (process.name : ("winword.exe", "explorer.exe", "w3wp.exe", "Dism.exe") or
51-
process.executable : ("?:\\Windows\\explorer.exe",
52-
"?:\\Program Files\\Microsoft Office\\root\\Office*\\WINWORD.EXE",
53-
"?:\\Program Files?(x86)\\Microsoft Office\\root\\Office*\\WINWORD.EXE",
54-
"?:\\Windows\\System32\\Dism.exe",
55-
"?:\\Windows\\SysWOW64\\Dism.exe",
56-
"?:\\Windows\\System32\\inetsrv\\w3wp.exe")
57-
)
49+
process.pe.original_file_name in ("WinWord.exe", "EXPLORER.EXE", "w3wp.exe", "DISM.EXE") and
50+
not process.executable : ("?:\\Windows\\explorer.exe",
51+
"?:\\Windows\\SyWOW64\\explorer.exe",
52+
"?:\\Program Files\\Microsoft Office\\root\\Office*\\WINWORD.EXE",
53+
"?:\\Program Files?(x86)\\Microsoft Office\\root\\Office*\\WINWORD.EXE",
54+
"?:\\Windows\\System32\\Dism.exe",
55+
"?:\\Windows\\SysWOW64\\Dism.exe",
56+
"?:\\Program Files (x86)\\Windows Kits\\10\\Assessment and Deployment Kit\\Deployment Tools\\amd64\\DISM\\dism.exe",
57+
"?:\\Windows\\System32\\inetsrv\\w3wp.exe",
58+
"?:\\Windows\\SysWOW64\\inetsrv\\w3wp.exe")
5859
'''
5960
note = """## Triage and analysis
6061

0 commit comments

Comments
 (0)