anvilogic
high
spl
Suspicious File written to Disk [splunk-winevent]
Adversaries may transfer tools or other files from an external system into a compromised environment. As seen with Solorigate when backdoor activates, the executing process (usually SolarWinds.BusinessLayerHost.exe) creates two files on disk. This use case looks for when dlls or vbs files added to Disk. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, APT31, APT34/OilRig, APT41, FIN7, Gamaredon (aka. Armageddon, UAC-0010), Gorgon Group, Harvester, Lazarus, Night Spider, TA413, TA551, Turla