华为乾坤EDR
云端依旧看不到 还是得挖日志(
执行到svchost.exe 就结束了
- [2023-10-29 00:32:31.571][Info] [5204] [GRAPH THREAT ROOT]: [filePath] C:\Windows\System32\wscript.exe, [rootType] EMPTY, [hitRule] TN0957
- [2023-10-29 00:32:31.573][Info] [5204] [HIPS ALERT]: Push, [ALERT INFO]: [threat_num]:TN0957, [severity]:1, [confidence_level]:50, [attack_count]:1, [ori_evt_count]:1, [disposal_count]:0
- [2023-10-29 00:32:31.573][Info] [5204] [HIPS ATTACK EVIDENCE]: [FILE INFO] [operation_type]:1, [pid]:4496, [process_name]:wscript.exe, [file_path]:C:\Users\RhineLab\AppData\Local\Temp\sXLo5VyYcIP9pELMy7PhawGELFbkCmWlhH1v3axdiFBgGEVrFedp24\svchost.exe, [attr]:32
- [2023-10-29 00:32:31.573][Info] [5204] [HIPS PERF ANALYSE]: [TIME CONSUME]:4(ms), [BYTE SIZE]:593
复制代码
|