Skip to content

[Rule Tuning] Modification of AmsiEnable Registry Key - Sysmon#1760

Merged
w0rk3r merged 2 commits intomainfrom
amsienable_sysmon
Feb 11, 2022
Merged

[Rule Tuning] Modification of AmsiEnable Registry Key - Sysmon#1760
w0rk3r merged 2 commits intomainfrom
amsienable_sysmon

Conversation

@w0rk3r
Copy link
Copy Markdown
Contributor

@w0rk3r w0rk3r commented Feb 7, 2022

Summary

Add support to Sysmon registry events

Copy link
Copy Markdown
Contributor

@DefSecSentinel DefSecSentinel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Copy Markdown
Contributor

@brokensound77 brokensound77 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - did you review other existing registry rules for similar compatibilities

@w0rk3r
Copy link
Copy Markdown
Contributor Author

w0rk3r commented Feb 11, 2022

@brokensound77 not yet, but it is already planned, and I expect it to be a lot of rules

Here is the issue: #1766

@w0rk3r w0rk3r merged commit 9c56b00 into main Feb 11, 2022
@w0rk3r w0rk3r deleted the amsienable_sysmon branch February 11, 2022 20:49
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants