Skip to content

Add T1140, T1059.006, T1548.003#6

Open
straysheep-dev wants to merge 1 commit intomicrosoft:mainfrom
straysheep-dev:add-rules/patch-1
Open

Add T1140, T1059.006, T1548.003#6
straysheep-dev wants to merge 1 commit intomicrosoft:mainfrom
straysheep-dev:add-rules/patch-1

Conversation

@straysheep-dev
Copy link
Copy Markdown

Comparing coverage with auditd this repo looks like the best place to start porting over and maintaining rules as I test them. I'm opening this pull request so that if these additions make sense, they become available here.

  • T1140 Deobfuscate/Decode Files or Information
  • T1059.006 Command and Scripting Interpreter: Python
  • T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching

If there's a better way to do this, please let me know. 👍

@straysheep-dev
Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant