HackTool - SysmonEOP Execution
Description
Detects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
Query · sigma
selection_img: Image|endswith: \SysmonEOP.exe selection_hash: Hashes|contains: - IMPHASH=22F4089EB8ABA31E1BB162C6D9BF72E5 - IMPHASH=5123FA4C4384D431CD0D893EEB49BBEC condition: 1 of selection_*
Known false positives
- Unlikely