Skip to content

Commit

Permalink
fix: new FP filter for RAS TSplus
Browse files Browse the repository at this point in the history
  • Loading branch information
phantinuss committed Jan 18, 2024
1 parent 72e511a commit 658f5c5
Showing 1 changed file with 5 additions and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ references:
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
author: Markus Neis
date: 2019/05/15
modified: 2023/04/20
modified: 2024/01/18
tags:
- attack.lateral_movement
- attack.t1021.001
Expand Down Expand Up @@ -61,6 +61,10 @@ detection:
Image|endswith: '\Ranger\SentinelRanger.exe'
filter_optional_firefox:
Image: 'C:\Program Files\Mozilla Firefox\firefox.exe'
fiter_optional_tsplus: # Some RAS
Image|endswith:
- ':\Program Files\TSplus\Java\bin\HTML5service.exe'
- ':\Program Files (x86)\TSplus\Java\bin\HTML5service.exe'
filter_optional_null:
Image: null
filter_optional_empty:
Expand Down

0 comments on commit 658f5c5

Please sign in to comment.