Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CLR Usage log #87

Open
ghost opened this issue May 1, 2023 · 1 comment
Open

CLR Usage log #87

ghost opened this issue May 1, 2023 · 1 comment

Comments

@ghost
Copy link

ghost commented May 1, 2023

REF: https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/

File Locations:

  • :\Users<user>\AppData\Local\Microsoft\CLR__(arch)\UsageLogs
  • :\Windows<System32|SysWOW6$=4>\config\systemprofile\AppData\Local\Microsoft\CLR__(arch)\UsageLogs

look for filenames with .log ext

Reg mod locations:

  • HKCU\SOFTWARE\Microsoft.NETFramework
  • HKLM\SOFTWARE\Microsoft.NETFramework

Reg key changes:

NGenAssemblyUsageLog
COMPlus_NGenAssemblyUsageLog

@ceramicskate0
Copy link
Owner

added
HKCU\SOFTWARE\Microsoft.NETFramework
HKLM\SOFTWARE\Microsoft.NETFramework
and that should cover NGenAssemblyUsageLog
COMPlus_NGenAssemblyUsageLog

file create rules appears to not exclude the directory location but it is not special in config either. But should capture log file creation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant