Hayabusa critical test sigma
Moriya Rootkit - System
Detects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report
Detection Logic
{
"system": {
"Channel": "System"
},
"selection": {
"Provider_Name": "Service Control Manager",
"EventID": 7045,
"ServiceName": "ZzNetSvc"
},
"condition": "system and selection"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...