Commit 463c1a0
Filip Olszak
Add current Acronis Cyber Protect service names to service-tamper rule
This rule already flags 'Acronis VSS Provider', 'AcronisAgent', and
'AcrSch2Svc' (legacy Acronis True Image/Backup service names) as
security-relevant services targeted by ransomware/tampering scripts.
Adds the current Acronis Cyber Protect (EDR/XDR) service/process
identifiers that weren't yet covered: AcronisCyberProtectionService,
AcronisActiveProtectionService, and aakore.
Sources: Acronis KB articles documenting Cyber Protect's installed
services.1 parent bc43378 commit 463c1a0
1 file changed
Lines changed: 4 additions & 1 deletion
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| |||
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
| 66 | + | |
66 | 67 | | |
| 68 | + | |
67 | 69 | | |
| 70 | + | |
68 | 71 | | |
69 | 72 | | |
70 | 73 | | |
| |||
0 commit comments