mitre-attack / car

Cyber Analytics Repository
Apache License 2.0
889 stars 300 forks source link

ADD : %windir% in CAR-2021-05-012.yaml #150

Closed EzLucky closed 2 years ago

EzLucky commented 2 years ago

I used this rule with the EventID 4697 and had cases where the service file path was starting with "%windir%\" which equals to "C:\Windows\" if Windows is installed on C:.

I didn't check if EventID 7045 translates "%windir%" to "C:\Windows", but I don't think so as %systemroot% is not translated in the event.

ikiril01 commented 2 years ago

Thanks! Seems like a nice addition to make the implementations more robust.