SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.73k stars 1.69k forks source link

ProxyEnable Setting in Registry #125

Closed Neo23x0 closed 3 years ago

Neo23x0 commented 4 years ago

Malware often disables a web proxy for 2nd stage downloads

E.g. https://app.any.run/tasks/7937e58a-105a-4196-8d9d-a1e9f41fd677#