elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[New] Execution via Windows Command Debugging Utility #3918

Closed Samirbous closed 3 weeks ago

Samirbous commented 2 months ago

https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/

CDB.exe can be used to exec shellcode or commands, its usually installed under programfiles (also some third party SW like HP ship it in programfiles):

image

protectionsmachine commented 2 months ago

Rule: New - Guidelines

These guidelines serve as a reminder set of considerations when proposing a new rule.

Documentation and Context

Rule Metadata Checks

New BBR Rules

Testing and Validation