Skip to content

Commit f956ae5

Browse files
committed
msxi aistubs
1 parent 3cd9e44 commit f956ae5

File tree

2 files changed

+15
-0
lines changed

2 files changed

+15
-0
lines changed
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Michael Haag
2+
id: kk9b2623-abd5-11eb-926b-120zf0943f11
3+
date: '2023-05-15'
4+
description: MSIX AI_STUBS execution detection for malicious installer packages
5+
environment: attack_range
6+
dataset:
7+
- https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1218/msix_ai_stubs/windows_sysmon.log
8+
sourcetypes:
9+
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
references:
11+
- https://attack.mitre.org/techniques/T1218
12+
- https://redcanary.com/threat-detection-report/techniques/installer-packages/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:4f6b0e90b70112e5d63f16310f5f4695be77c542871b88a7fe696914637488d5
3+
size 1736

0 commit comments

Comments
 (0)