Skip to content

Suspicious Microsoft Office Child Process detection rule#432

Open
driverenok wants to merge 7 commits into
Security-Experts-Community:masterfrom
driverenok:feature/suspicious_microsoft_office_child_process
Open

Suspicious Microsoft Office Child Process detection rule#432
driverenok wants to merge 7 commits into
Security-Experts-Community:masterfrom
driverenok:feature/suspicious_microsoft_office_child_process

Conversation

@driverenok
Copy link
Copy Markdown

Детект создания дочернего процесса приложением MS Office. Правило основано на публикации Снова пропустили момент запуска фишингового вложения?

Перечень процессов MS Office:

"winword.exe", "excel.exe", "powerpnt.exe", "visio.exe", "mspub.exe", "eqnedt32.exe", "outlook.exe", "eqnedt32.exe", "msosync.exe", "msaccess.exe", "onenote.exe", "winproj.exe", "wordpad.exe", "wordview.exe"

driverenok and others added 7 commits July 16, 2024 23:07
Signed-off-by: Andru <43377995+driverenok@users.noreply.github.com>
Signed-off-by: Andru <43377995+driverenok@users.noreply.github.com>
Signed-off-by: Andru <43377995+driverenok@users.noreply.github.com>
@aw350m33d
Copy link
Copy Markdown

Нужно добавить ТС с легитимными дочерними процессами, иначе будет много ложных сработок. Я уже сформировал часть такого списка. Залью апдейт)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants