SigmaHQ / sigma

Main Sigma Rule Repository
Other
7.84k stars 2.12k forks source link

Filter Driver Unloaded Via Fltmc.EXE #4874

Closed celalettin-turgut closed 5 days ago

celalettin-turgut commented 3 weeks ago

Rule UUID

4d7cda18-1b12-4e52-b45c-d28653210df8

Example EventLog

ActionType:ProcessCreated FileName: fltMC.exe FolderPath: C:\Windows\System32\fltMC.exe ProcessCommandLine: fltmc.exe unload DFMFilter InitiatingProcessFileName:DCFAService64.exe InitiatingProcessCommandLine: DCFAService64.exe -stop DFMFilter InitiatingProcessFolderPath: c:\program files (x86)\manageengine\uems_agent\bin\dcfaservice64.exe InitiatingProcessParentFileName: dcconfig.exe

Description

Legitimate behaviour from manageengine. Log has been extracted from Microsoft Defender

nasbench commented 5 days ago

Will be fixed in #4872