Browse Rules

Search and filter across all detection sources

207 rules

sentinel high kql

Google DNS - UNC2452 (Nobelium) APT Group activity

'Detects UNC2452 (Nobelium) APT Group activity.'

signature-base unknown yara

APT_APT29_NOBELIUM_Malware_May21_2 [yara]

Detects malware used by APT29 / NOBELIUM

signature-base unknown yara

APT_APT29_NOBELIUM_Malware_May21_3 [yara]

Detects malware used by APT29 / NOBELIUM

signature-base unknown yara

APT_APT29_NOBELIUM_Malware_May21_4 [yara]

Detects malware used by APT29 / NOBELIUM

signature-base unknown yara

APT_APT29_NOBELIUM_BoomBox_May21_2 [yara]

Detects BoomBox malware used by APT29 / NOBELIUM

signature-base unknown yara

APT_APT29_NOBELIUM_BoomBox_May21_1 [yara]

Detects BoomBox malware as described in APT29 NOBELIUM report

signature-base unknown yara

APT_APT29_NOBELIUM_Stageless_Loader_May21_2 [yara]

Detects stageless loader as used by APT29 / NOBELIUM

signature-base unknown yara

APT_APT29_NOBELIUM_JS_EnvyScout_May21_1 [yara]

Detects EnvyScout deobfuscator code as used by NOBELIUM group

signature-base unknown yara

APT_APT29_NOBELIUM_JS_EnvyScout_May21_2 [yara]

Detects EnvyScout deobfuscator code as used by NOBELIUM group

signature-base unknown yara

APT_APT29_NOBELIUM_LNK_NV_Link_May21_2 [yara]

Detects NV Link as used by NOBELIUM group

signature-base unknown yara

APT_APT29_NOBELIUM_NativeZone_Loader_May21_1 [yara]

Detects NativeZone loader as described in APT29 NOBELIUM report

signature-base unknown yara

APT_APT29_NOBELIUM_LNK_Samples_May21_1 [yara]

Detects link file characteristics as described in APT29 NOBELIUM report

signature-base unknown yara

APT_APT29_NOBELIUM_BoomBox_PDF_Masq_May21_1 [yara]

Detects PDF documents as used by BoomBox as described in APT29 NOBELIUM report

sekoia unknown yara

apt_nobelium_acrobox_downloader_apr2022 [yara_rules]

Detects AcroBox downloader

sekoia unknown yara

apt_nobelium_nativezone_gen [yara_rules]

Detects NativeZone used in 2022

signature-base unknown yara

MAL_CRIME_Unknown_ISO_Jun21_1 [yara]

Triggers on ISO files that mimick NOBELIUM TTPs, but uses LNK files that call powershell instead.

anvilogic high spl

Request Random Generated SubDomain DGA (Proxy) [splunk-proxy]

Detection of request made to a randomly generated subdomain. - Threat Actor Association: APT29/Nobelium/Cozy Bear, APT34/OilRig

sigma critical sigma

FoggyWeb Backdoor DLL Loading

Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll

hayabusa critical sigma

FoggyWeb Backdoor DLL Loading

Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll

anvilogic high other

Certutil Obfuscate_Encode Files [snowflake-crowdstrikefdr_process]

Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti

anvilogic high spl

Powersploit SPN Enumeration [splunk-powershell]

Kerberoast is a series of tools for attacking MS Kerberos implementations. Threat Actor Association: APT29/Nobelium/Cozy Bear Software Association: Cuba, Vice Society #TrendingThreat #Russia #Ukraine Atomics T1558.003 #Test1

anvilogic high spl

Certutil Obfuscate_Encode Files [splunk-edr]

Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti

anvilogic high spl

Certutil Obfuscate_Encode Files [splunk-powershell]

Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti

anvilogic high spl

Certutil Obfuscate_Encode Files [splunk-sysmon]

Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti

anvilogic high spl

Certutil Obfuscate_Encode Files [splunk-winevent]

Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti