Google Chronicle unknown experimental yara-l
malware_zeppelin_registry
Zeppelin registry key writing
Detection Logic
/*
* Copyright 2021 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES
OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
rule malware_zeppelin_registry
{
meta:
author = "Google Cloud Security"
description = "Zeppelin registry key writing"
reference = "https://attack.mitre.org/techniques/T1112/"
related_sample = "423ac94365660904322647356081aa1ea584cb20385ec3163193e71fd3e4f1ad"
yara_version = "YL2.0"
rule_version = "1.0"
events:
$e1.metadata.event_type = "REGISTRY_CREATION"
re.regex($e1.target.registry.registry_key, `\\software\\zeppelin\\`) nocase
condition:
$e1
} Field Validations
Loading…
Comments (0)
Loading comments...