Skip to content

Added rules to detect lolbas provlaunch.exe and also filter on legitimate system non-wmiprvse processes loading WMI modules #13111

Added rules to detect lolbas provlaunch.exe and also filter on legitimate system non-wmiprvse processes loading WMI modules

Added rules to detect lolbas provlaunch.exe and also filter on legitimate system non-wmiprvse processes loading WMI modules #13111

Triggered via pull request August 2, 2023 05:51
Status Success
Total duration 7m 55s
Artifacts

sigma-test.yml

on: pull_request
test-sigma-logsource
49s
test-sigma-logsource
test-sigma
6m 8s
test-sigma
check-baseline-win7
5s
check-baseline-win7
check-baseline-win10
2m 15s
check-baseline-win10
check-baseline-win11
4m 32s
check-baseline-win11
check-baseline-win2022
29s
check-baseline-win2022
check-baseline-win2022-domain-controller
1m 1s
check-baseline-win2022-domain-controller
check-baseline-win2022-0-20348-azure
2m 51s
check-baseline-win2022-0-20348-azure
Fit to window
Zoom out
Zoom in