ceramicskate0 / sysmon-config

CeramicSkate0 Sysmon configuration fork file template with default high-quality event tracing
https://github.com/ceramicskate0/sysmon-config
10 stars 0 forks source link

CLR Usage log #87

Open ghost opened 1 year ago

ghost commented 1 year ago

REF: https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/

File Locations:

look for filenames with .log ext

Reg mod locations:

Reg key changes:

NGenAssemblyUsageLog COMPlus_NGenAssemblyUsageLog

ceramicskate0 commented 1 year ago

added HKCU\SOFTWARE\Microsoft.NETFramework HKLM\SOFTWARE\Microsoft.NETFramework and that should cover NGenAssemblyUsageLog COMPlus_NGenAssemblyUsageLog

file create rules appears to not exclude the directory location but it is not special in config either. But should capture log file creation