-
Hi, thanks for your effort in developing this enumeration script. It's a really nice project and it is really useful for engagements to quickly find privesc vulns, however, sadly this is only fully us…
-
Add an option to log information about elevated processes. Logging should be available either while a user is administrator, or always.
-
**Describe the bug**
The default query for the SIEM rule "Net command via SYSTEM account" appears to be incorrect.
**To Reproduce**
Default query:
```
process where event.type in ("start", "pro…
-
## Description
Rules that support sysmon and uses the `user.id` field are prone to FPs and FNs because sysmon don't really have `user.id` data, as per this screenshot as an example:
![image](htt…
-
Hello,
I am using nodejs load dll A and then dll A load dll B which internal calls IGraphicsCaptureItemInterop.CreateForWindow but I encounter winrt::hresult_access_denied
when I using MFC just to l…
-
- Agent version: 7.7.1 and 7.10.2
- Operating System: Windows 10
Directed by Elastic consultant to post this as a bug.
winlogbeat logs with event.code 5152 and 5156 showing fields that are not …
-
The following issue aims to run the specified test for the current release candidate, report the results, and open new issues for any encountered errors.
## Test information
| …
-
### Windows Terminal version (or Windows build number)
1.11.2921.0
### Other Software
wsl.exe (10.0.22000.1)
### Steps to reproduce
Loading Windows Terminal will launch `wsl.exe` despite Windows …
-
This issue aims to test manually Emotet malware to define the requirements to develop an automated E2E test.
To achieve this we will follow these guides:
- https://github.com/wazuh/wazuh-automatio…
-
| Target version | Related issue | Related PR |
|--------------------|--------------------|-----------------|
| 4.4 | https://github.com/wazuh/wazuh/issues/13099 | https://github.com/wazuh/wazuh/pul…