NextronSystems / aurora-agent-lite

Repository to handle issues with our free EDR agent Aurora Lite
25 stars 0 forks source link

Potential Bitlocker Issue: Aurora mounts external folder, when mount doesn't exist for that path #10

Open AlphaKnightRadiant opened 5 months ago

AlphaKnightRadiant commented 5 months ago

Issue where Aurora Agent Is mounting certain folders that Exist in C:/ for basic windows paths (program files, system32etc) and mounts them as F:/4/Windows

The F drive exists, but no F:/4/ path exists.

This leads to sigma rulesets firing for "unusual folder" when the folder path has been mistakenly set by aurora agent.

Screenshot for context.

image

Proof path doesn't exist:

image

nasbench commented 1 month ago

cc @secDre4mer