capa-rules
capa-rules copied to clipboard
add coverage for process manipulation via WMI Win32_Process
The Win32_Process WMI class represents a process on an operating system.
https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/create-method-in-class-win32-process https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/terminate-method-in-class-win32-process
similar to #470.
create process via Win32_Process:
...
- and:
- string: "Win32_Process"
- or:
- string: "Create"
terminate process via Win32_Process:
...
- and:
- string: "Win32_Process"
- or:
- string: "Terminate"