Rule Info
Name
ADS Zone.Identifier Deleted By Uncommon Application
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
Date
2023-09-04 00:00:00
Modified
2024-04-26 00:00:00
Id
3109530e-ab47-4cc6-a953-cac5ebcc93ae
Tags
attack.defense-evasion attack.t1070.004 DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
Merge PR #4837 from @nasbench - fix fp reported in #4820
2024-04-26
frack113
Merge PR #4419 from @frack113 - New Rules Related To Zone.Identifier ADS Deletion
2023-09-06