Open arvindersingh-qasource opened 1 year ago
Describe the bug Adversary File Alerts not generating with executing respective files
Build Details
Web link : https://34.42.103.232/ Version : smp-dev-3-50-0-20ab71a-1084 Sensor : 3.64.4
Browser Details This issue is occurring on all browsers.
Preconditions
Steps to Reproduce
Unusual Process ExecutiON Path - WBEM
Windows File Masquerading
Incoming DCOM Lateral Movement with MMC
DLL Search Order Hijack Attack
Bypass UAC via Sdclt
Activity timeline on updating Permission theft protection in implemented policy
Actual Result Adversary File Alerts not generating with executing respective files
Expected Result Adversary File Alerts should be generating with executing respective files or provide any work around to generate the above mentioned Alerts.
Reviewed and assigned to @charlie-pichette !!
@brokensound77 is this something your team handles?
Describe the bug Adversary File Alerts not generating with executing respective files
Build Details
Browser Details This issue is occurring on all browsers.
Preconditions
Steps to Reproduce
Type of Alerts
Unusual Process ExecutiON Path - WBEM
unusual_process_path.py.txt
Windows File Masquerading
process_name_masquerade.py.txt
Incoming DCOM Lateral Movement with MMC
dcom_lateral_movement_with_mmc.py.txt
DLL Search Order Hijack Attack
uac_sysprep.py.txt
Bypass UAC via Sdclt
uac_sdclt.py.txt
Activity timeline on updating Permission theft protection in implemented policy
tokentheft64.exe.txt
Actual Result Adversary File Alerts not generating with executing respective files
Expected Result Adversary File Alerts should be generating with executing respective files or provide any work around to generate the above mentioned Alerts.