Je hebt een klacht over de onderstaande posting:
Mocht je dit soort dingen willen detecteren en MS Defender gebruiken: // bron: https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix DeviceRegistryEvents | where RegistryKey endswith @"\Explorer\RunMRU" | where RegistryValueName != "MRUList" | where RegistryValueData has_any ( "powershell", "cmd", "mshta", "wscript", "cscript", "certutil", "rundll32", "regsvr32", "curl", "Invoke-WebRequest", "Invoke-Expression", "IEX", "-enc", "-EncodedCommand") | project Timestamp = TimeGenerated, DeviceId, DeviceName, RegistryKey, RegistryValueName, RegistryValueData, InitiatingProcessAccountName, InitiatingProcessCommandLine, ReportId
Beschrijf je klacht (Optioneel):