SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.8k stars 1.71k forks source link

Other persistence methods - SHIM, ServerLevelPluginDll #25

Closed Neo23x0 closed 3 years ago

Neo23x0 commented 7 years ago

https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html

SwiftOnSecurity commented 3 years ago

Hi @Neo23x0 I'm sorry this took so long, I get really anxious about this file now. It looks like I merged in these changes already somehow. Thank you