Elastic Defend high stable eql

Potential DANTE Spyware Execution

Identifies potential execution of a commercial spyware.

View Source

Detection Logic

registry where event.action == "query" and registry.value == "ComputerName" and
 process.thread.Ext.call_stack_summary like "ntdll.dll*
| kernelbase.dll
| rpcrt4.dll
| wevtapi.dll
| *" and
 _arraysearch(process.thread.Ext.call_stack, $entry,
              $entry.callsite_trailing_bytes like ("488bd848894424384885c00f84bc0000008974244033c955e8*",
                                                   "4883c320483bdf????488b7dd8488b5dd0418bf6488b4de8483b4df0400f95c64885db????488bd7488bcb*"))

Field Validations

Loading…

Comments (0)

Loading comments...