elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.97k stars 500 forks source link

[Rule Tuning] Suspicious Antimalware Scan Interface DLL #2803

Closed NC-Netrunner closed 1 year ago

NC-Netrunner commented 1 year ago

Link to rule

https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_amsi_bypass_dllhijack.toml

Description

Miss-spell on line 112. "Distribuition" should be "Distribution" for the exception to work.

w0rk3r commented 1 year ago

Thanks for bringing this one to our attention, we are going to fix it as part of https://github.com/elastic/detection-rules/pull/2850