lvferdi
11/29/2021, 9:00 PM$start = Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\wuauserv" | Select-Object -ExpandProperty "Start"
Attack successful if zero exit
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\wuauserv" -Name "Start" -Value 4 -Force
Attack successful if zero exit
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\wuauserv" | Select-Object -ExpandProperty "Start"
Attack successful if output matches /4/
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\wuauserv" -Name "Start" -Value $start -Force
When I execute this with target_name: { include: { values [ * ] } }
, I get the results I would expect but if I add
"target_name": {
"include": {
"values": [
"*\\Start",
]
}
}
I get no results.
Expected outcome is that since the resulting registry entry ends with \Start
the include filter for *\\Start
would be enough to capture the information.himanshu
11/30/2021, 8:05 AMwin_registry_events
filters.lvferdi
11/30/2021, 12:53 PMhimanshu
11/30/2021, 1:11 PMwin_registry_events
?
"target_name": {
"include": {
"values": [
"*\\Start"
]
}
}
lvferdi
11/30/2021, 1:12 PM"win_registry_events": {
"action": {
"exclude": {
"values": [
"REG_CREATE"
]
}
},
"target_name": {
"include": {
"values": [
"*"
]
}
},
"process_name": {
"exclude": {
"values": [ "C:\\WINDOWS\\system32\\svchost.exe",
"C:\\WINDOWS\\SysWOW64\\F5FltSrv.exe",
"System",
"C:\\WINDOWS\\system32\\lsass.exe",
"C:\\ProgramData\\Core\\VPNCC.exe",
"C:\\WINDOWS\\system32\\wbem\\wmiprvse.exe",
"C:\\Program Files (x86)\\OpenText\\Office Editor\\OTEditTray.exe",
"C:\\WINDOWS\\SysWOW64\\AbtSvcHost_.exe",
"C:\\Program Files (x86)\\NVIDIA Corporation\\Update Core\\NvBackend.exe",
"C:\\WINDOWS\\SysWOW64\\netsh.exe",
"C:\\Program Files\\Windows Event Reporting\\Core\\EventReporting.AgentService.exe",
"C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
"*\\AppData\\Local\\Akamai\\netsession_win.exe",
"C:\\Windows\\winipbin\\*"
]
}
}
},
This works as expected, when I put the "*\\Start
in the config it no longer sees the datahimanshu
11/30/2021, 1:27 PMOpenPlgx
11/30/2021, 3:14 PMlvferdi
11/30/2021, 8:13 PMhimanshu
12/01/2021, 11:38 AM