Sagan critical stable other
[CROWDSTRIKE] Machine Learning Tactic Catchall
[CROWDSTRIKE] Machine Learning Tactic Catchall
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Machine Learning Tactic Catchall"; program:CrowdStrike; content:"cat=Machine Learning"; content:!"msg=This file meets the File Analysis ML algorithm's lowest-confidence threshold for malware"; content:!"Document Access In"; meta_content:!"%sagan%",A file written to the file-system meets the cloud-based machine learning model high confidence threshold for malicious files,A file written to the file-system meets the cloud-based machine learning model medium confidence threshold for malicious files,A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files,A file written to the file system meets the on-sensor machine learning medium confidence threshold for malicious files,An Office file with a macro written to the file system meets the File Analysis ML algorithm's high-confidence threshold for malware,Network access in an EPP detection summary event,Quarantined files in a detection summary event,Quarantined files in an EPP detection summary event,This file meets the Adware/PUP Anti-malware ML algorithm's high-confidence threshold,This file meets the File Analysis ML algorithm's high-confidence threshold for malware,This process wrote a suspicious file to disk. That associated file meets the Adware/PUP Anti-malware ML algorithm's high-confidence threshold,This process wrote a suspicious file to disk. That associated file meets the ML algorithm's high-confidence adware/PUP detection threshold; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016652; rev: 3; metadata:created_at 2025_06_25, updated_at 2026_03_26;) Field Validations
Loading…
Comments (0)
Loading comments...