Closed jtothej closed 3 months ago
Update encrypt-data-using-dpapi.yml rule - add RtlEncryptMemory/SystemFunction040 and RtlDecryptMemory/SystemFunction041. CryptProtectMemory and CryptUnprotectMemory are wrappers for SystemFunction040 and SystemFunction041 respectively.
RtlEncryptMemory
SystemFunction040
RtlDecryptMemory
SystemFunction041
CryptProtectMemory
CryptUnprotectMemory
Update encrypt-data-using-dpapi.yml rule - add
RtlEncryptMemory
/SystemFunction040
andRtlDecryptMemory
/SystemFunction041
.CryptProtectMemory
andCryptUnprotectMemory
are wrappers forSystemFunction040
andSystemFunction041
respectively.