Skip to content

win_susp_regsvr32_flags_anomaly.yml #3674

Closed Answered by frack113
AlphaKiloDelta asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,
for proc_creation_win_susp_regsvr32_flags_anomaly.yml :
The normal behavior is /i /n
We want to detect when use with only /i.

In theTwitter https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/cobalt_upd_ttps/ the malware use only /s /i

Replies: 1 comment 6 replies

Comment options

You must be logged in to vote
6 replies
@nasbench
Comment options

@AlphaKiloDelta
Comment options

@nasbench
Comment options

@AlphaKiloDelta
Comment options

@nasbench
Comment options

Answer selected by nasbench
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants