Elastic Defend high stable eql
Potential DANTE Spyware Execution
Identifies potential execution of a commercial spyware.
Detection Logic
registry where event.action == "query" and registry.value == "ComputerName" and
process.thread.Ext.call_stack_summary like "ntdll.dll*
| kernelbase.dll
| rpcrt4.dll
| wevtapi.dll
| *" and
_arraysearch(process.thread.Ext.call_stack, $entry,
$entry.callsite_trailing_bytes like ("488bd848894424384885c00f84bc0000008974244033c955e8*",
"4883c320483bdf????488b7dd8488b5dd0418bf6488b4de8483b4df0400f95c64885db????488bd7488bcb*")) Field Validations
Loading…
Comments (0)
Loading comments...