Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(rules): New
Image load via NTFS transaction
rule
Identifies image loading of a file written to disk via NTFS transaction. Adversaries may exploit the transactional API to execute code in the address space of the running process without committing the code to disk.
- Loading branch information