Sagan critical stable other

[CROWDSTRIKE] Execution Tactic Catchall

[CROWDSTRIKE] Execution Tactic Catchall

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Execution Tactic Catchall"; program:CrowdStrike; content:"cat=Execution"; parse_src_ip:1; normalize; content:!"msg=A number of behaviors occurred indicative of the Empyre Backdoor tool"; content:!"nessus"; nocase; content:!"DetectionSummaryEvent"; content:!"Document Access In A Detection Summary Event"; content:!"ScheduledReportNotificationEvent"; content:!"IdpDetectionSummaryEvent"; content:!"AutomatedLeadSummaryEvent"; meta_content:!"%sagan%",An obfuscated command line attempted to launch an unusual script,A number of behaviors occurred indicative of the Empyre Backdoor tool,A PowerShell process downloaded and launched a remote file.,A PowerShell script related to this process is likely malicious or shares characteristics with known malicious scripts,A suspicious process leveraged mshta in an attempt to download and execute a payload,A suspicious process was identified by CrowdStrike,A suspicious script launched that might be related to malicious activity,A user executed a PsExec command on a DC for the first time,A user executed a scheduled task RPC DCE/RPC command targeting a DC for the first time; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016646; rev:2; metadata:created_at 2025_06_25, updated_at 2026_03_26;)

Field Validations

Loading…

Comments (0)

Loading comments...