Sagan critical stable other

[CROWDSTRIKE] Defense Evasion Tactic Catchall

[CROWDSTRIKE] Defense Evasion Tactic Catchall

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Defense Evasion Tactic Catchall"; program:CrowdStrike; content:"cat=Defense Evasion"; content:!"AutomatedLeadSummaryEvent"; meta_content:!"%sagan%",A file appears to be imitating a standard OS or otherwise benign filename and/or launched from an unusual location,An executable appears to have been manipulated to evade detection,A process appears to be tampering with the Falcon sensor configuration,A process attempted to modify a Falcon sensor folder,A process attempted to modify an auxiliary Falcon sensor service configuration via the registry,A process attempted to modify a registry key or value used by Falcon sensor,A process attempted to modify BFE firewall rules managed by Falcon sensor via the registry,A process attempted to modify Falcon sensor auxiliary driver files,A process attempted to modify Falcon sensor configuration via the registry,A process attempted to modify Falcon sensor core driver files,A process attempted to modify Falcon sensor installer related files,A process attempted to modify Falcon sensor related service binaries,A process attempted to modify Falcon sensor service configuration via the registry,A process attempted to modify files used for Falcon sensor dynamic configuration,A process attempted to modify injected libraries used by Falcon sensor,A process attempted to modify the configuration of a COM object registered by Falcon sensor,A process attempted to modify the Image File Execution Options for a Falcon sensor executable,A process attempted to modify the system AMSI provider configuration via the configuration,A process attempted to perform a file system operation in a protected Falcon folder location,A process attempted to remove CsDeviceControl from the registry,A process attempted to remove CsDeviceControl from the registry for a customer with the device control SKU,A process loaded a module associated with known malware,A service host process launched suspended under an unusual parent,A suspicious process injected into another process in an unusual way,A suspicious process is attempting to disable or modify security tools,Mshta attempted to load a likely malicious command line from a registry entry using an obfuscated script,Msiexec launched with unusual arguments; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016645; rev:2; metadata:created_at 2025_06_25, updated_at 2026_03_26;)

Field Validations

Loading…

Comments (0)

Loading comments...