Sagan critical stable other

[CROWDSTRIKE] Impact Tactic Catchall

[CROWDSTRIKE] Impact Tactic Catchall

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Impact Tactic Catchall"; program:CrowdStrike; content:"cat=Impact"; meta_content:!"%sagan%",A process attempted to hide a Volume Shadow Snapshot,A process deleted a system backup,Ransomware file operation activity has been observed occurring over a remote SMB connection,technique=Data Encrypted for Impact,The BCDEdit tool was used to disable operating system recovery features; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016650; rev:2; metadata:created_at 2025_06_25, updated_at 2026_03_26;)

Field Validations

Loading…

Comments (0)

Loading comments...