Skip to content

Added rules to detect lolbas provlaunch.exe and also filter on legitimate system non-wmiprvse processes loading WMI modules #13120

Added rules to detect lolbas provlaunch.exe and also filter on legitimate system non-wmiprvse processes loading WMI modules

Added rules to detect lolbas provlaunch.exe and also filter on legitimate system non-wmiprvse processes loading WMI modules #13120

Triggered via pull request August 2, 2023 13:54
Status Success
Total duration 9m 1s
Artifacts

sigma-test.yml

on: pull_request
test-sigma-logsource
42s
test-sigma-logsource
test-sigma
7m 21s
test-sigma
check-baseline-win7
5s
check-baseline-win7
check-baseline-win10
2m 4s
check-baseline-win10
check-baseline-win11
3m 8s
check-baseline-win11
check-baseline-win2022
32s
check-baseline-win2022
check-baseline-win2022-domain-controller
54s
check-baseline-win2022-domain-controller
check-baseline-win2022-0-20348-azure
4m 5s
check-baseline-win2022-0-20348-azure
Fit to window
Zoom out
Zoom in