Sagan critical stable other
[CROWDSTRIKE] Command and Control Tactic Catchall
[CROWDSTRIKE] Command and Control Tactic Catchall
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Command and Control Tactic Catchall"; program:CrowdStrike; content:"tactic=Command and Control"; meta_content:!"%sagan%",Network Access In A Detection Summary Event,Document Access In A Detection Summary Event; content:!"Certutil was observed downloading file(s) from a remote location"; content:!"A process attempted to establish an unusual connection over a commonly used port, possibly to a command and control server"; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016643; rev:2; metadata:created_at 2025_06_25, updated_at 2026_03_26;) Field Validations
Loading…
Comments (0)
Loading comments...