Add sysmon integ check feature addition #114
Labels
App Enhancement
Something to make app better or change to current feature
New Feature
Additional feature to add
Searching File Change
Something that changes to Searchs.txt in Repo
Security Enhancment
Not a software vuln. But could/should be something that could be done to better protect software.
Based on POC at https://github.com/matterpreter/Shhmon an uploaded bad sysmon driver caused crash of sysmon. While IOCs are there the current integ check SWELF does may not by default find this. This shoul dbe built into app due to reliance on sysmon working. (SWELF will not fix or resolve issue but should alert when found per run).
IOCs to add to example Seachs.txt file and Sysmon Event ID 255 into application for sec_check():
The text was updated successfully, but these errors were encountered: