New Suspicious Assemblies Installed Via Gacutil.EXE

Rule Info

Name
New Suspicious Assemblies Installed Via Gacutil.EXE
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the addition of new assemblies to the global assembly cache (GAC) via the the "Gacutil" utility from suspicious locations
Date
2023-02-01 00:00:00
Modified
None
Id
1b943dd1-5daf-43b2-8daf-81245a953bd5
Tags
attack.execution attack.t1059
Type
Nextron Sigma feed only (private)

Rule History