SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.68k stars 1.69k forks source link

Monitor for .js files for Microsoft JScript #146

Open KevinDeNotariis opened 3 years ago

KevinDeNotariis commented 3 years ago

These files (.js) might be potential infection vectors, since Microsoft supports them natively. A .js file can simply be run in Windows with Wscript file.jsorCscript file.js`. It might clutter the logs for a Javascript developer but it will be beneficial for every other user.