microsoft / Microsoft-365-Defender-Hunting-Queries

Sample queries for Advanced hunting in Microsoft 365 Defender
MIT License
1.94k stars 539 forks source link

Add modification-of-exefile-shell-open-key.md #431

Open Karneades opened 3 years ago

Karneades commented 3 years ago

Add first detection of the exefile shell open key to the repo. See also https://twitter.com/swisscom_csirt/status/1461686311769759745 for a short description. It is currently used by Lokibot for persistence. Sneaky! Once in a while not only tasks, services or run keys are used, yay!

ghost commented 3 years ago

CLA assistant check
All CLA requirements met.