Techniques
Sample rules
REGISTER_APP.VBS Proxy Execution
- source: sigma
- technicques:
- t1218
Description
Detects the use of a Microsoft signed script ‘REGISTER_APP.VBS’ to register a VSS/VDS Provider as a COM+ application.
Detection logic
condition: selection
selection:
CommandLine|contains|all:
- \register_app.vbs
- -register