sans-blue-team / DeepBlueCLI

GNU General Public License v3.0
2.16k stars 352 forks source link

Wmi events #25

Closed netscylla closed 1 year ago

netscylla commented 3 years ago

Added code to support potential detection of malicious WMI Events from "Microsoft-Windows-WMI-Activity/Operational"

T1546.003 : Persistence - WMI - Event Triggered Execution