|
2 | 2 | creation_date = "2020/08/14" |
3 | 3 | integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"] |
4 | 4 | maturity = "production" |
5 | | -updated_date = "2025/03/20" |
| 5 | +updated_date = "2025/08/13" |
6 | 6 |
|
7 | 7 | [rule] |
8 | 8 | author = ["Elastic"] |
@@ -87,54 +87,55 @@ event.category : "file" and host.os.type : "windows" and event.type : "creation" |
87 | 87 |
|
88 | 88 |
|
89 | 89 | [[rule.filters]] |
90 | | - |
91 | 90 | [rule.filters.meta] |
92 | 91 | negate = false |
93 | 92 | [rule.filters.query.wildcard."file.path"] |
94 | 93 | case_insensitive = true |
95 | 94 | value = "?:\\\\Windows\\\\Sys?????\\\\*" |
96 | | -[[rule.filters]] |
97 | 95 |
|
| 96 | +[[rule.filters]] |
98 | 97 | [rule.filters.meta] |
99 | 98 | negate = true |
100 | 99 | [rule.filters.query.wildcard."file.path"] |
101 | 100 | case_insensitive = true |
102 | 101 | value = "?:\\\\Windows\\\\Sys?????\\\\PrintConfig.dll" |
103 | | -[[rule.filters]] |
104 | 102 |
|
| 103 | +[[rule.filters]] |
105 | 104 | [rule.filters.meta] |
106 | 105 | negate = true |
107 | 106 | [rule.filters.query.wildcard."file.path"] |
108 | 107 | case_insensitive = true |
109 | | -value = "?:\\Windows\\Sys?????\\u005lrs.dll" |
110 | | -[[rule.filters]] |
| 108 | +value = "?:\\\\Windows\\\\Sys?????\\\\x5lrs.dll" |
111 | 109 |
|
| 110 | +[[rule.filters]] |
112 | 111 | [rule.filters.meta] |
113 | 112 | negate = true |
114 | 113 | [rule.filters.query.wildcard."file.path"] |
115 | 114 | case_insensitive = true |
116 | | -value = "?:\\Windows\\system32\\spool\\DRIVERS\\u0064\\\\*.dll" |
117 | | -[[rule.filters]] |
| 115 | +value = "?:\\\\Windows\\\\system32\\\\spool\\\\DRIVERS\\\\x64\\\\*.dll" |
118 | 116 |
|
| 117 | +[[rule.filters]] |
119 | 118 | [rule.filters.meta] |
120 | 119 | negate = true |
121 | 120 | [rule.filters.query.wildcard."file.path"] |
122 | 121 | case_insensitive = true |
123 | 122 | value = "?:\\\\Windows\\\\system32\\\\spool\\\\DRIVERS\\\\W32X86\\\\*.dll" |
124 | | -[[rule.filters]] |
125 | 123 |
|
| 124 | +[[rule.filters]] |
126 | 125 | [rule.filters.meta] |
127 | 126 | negate = true |
128 | 127 | [rule.filters.query.wildcard."file.path"] |
129 | 128 | case_insensitive = true |
130 | | -value = "?:\\Windows\\system32\\spool\\PRTPROCS\\u0064\\\\*.dll" |
131 | | -[[rule.filters]] |
| 129 | +value = "?:\\\\Windows\\\\system32\\\\spool\\\\PRTPROCS\\\\x64\\\\*.dll" |
132 | 130 |
|
| 131 | +[[rule.filters]] |
133 | 132 | [rule.filters.meta] |
134 | 133 | negate = true |
135 | 134 | [rule.filters.query.wildcard."file.path"] |
136 | 135 | case_insensitive = true |
137 | 136 | value = "?:\\\\Windows\\\\system32\\\\spool\\\\{????????-????-????-????-????????????}\\\\*.dll" |
| 137 | + |
| 138 | + |
138 | 139 | [[rule.threat]] |
139 | 140 | framework = "MITRE ATT&CK" |
140 | 141 | [[rule.threat.technique]] |
|
0 commit comments