A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
4.01k
stars
807
forks
source link
Typo in FileCreate rule in T1138_appcompat.xml #8
Closed
mattifestation closed 6 years ago
The
TargetFileName
element should beTargetFilename
. Changing it will allow sysmon.exe to consume the config.