Amsi.DLL Load By Uncommon Process

Rule Info

Tags
attack.defense_evasion attack.t1490 attack.impact DEMO
Modified
None
Author
frack113
Name
Amsi.DLL Load By Uncommon Process
Description
Detects loading of Amsi.dll by uncommon processes
Date
2023-03-12 00:00:00
Id
facd1549-e416-48e0-b8c4-41d7215eedc8
Type
Community Rule

Rule History

Commit
Date
Author
Title
2023-03-12
frack113
feat: new rule `amsi.dll load by uncommon process` (#4102)