unfetter-analytic icon indicating copy to clipboard operation
unfetter-analytic copied to clipboard

Create 5 Analytics with Scripts to generate attack

Open infosec-alchemist opened this issue 7 years ago • 1 comments

Create five analytics, with corresponding attacker scripts to generate the data.

  • [x] Event Log Wipe
  • [x] regsvr32.exe usage - https://attack.mitre.org/wiki/Technique/T1117
  • [ ] InstallUtil usage - https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Execution/InstallUtil.md

infosec-alchemist avatar Jan 10 '18 20:01 infosec-alchemist

We may need to install microsoft.net to make this work properly

infosec-alchemist avatar Jan 10 '18 20:01 infosec-alchemist