Sagan critical stable other
[CROWDSTRIKE] Malware Tactic Catchall
[CROWDSTRIKE] Malware Tactic Catchall
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Malware Tactic Catchall"; program:CrowdStrike; content:"cat=Malware"; meta_content:!"%sagan%",A file written to the file-system was classified as Adware/PUP based on its SHA256 hash,A process launched whose behavior is likely related to a potentially unwanted program (PUP),A process launched with a filename, path, and/or arguments associated with known adware; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016653; rev:2; metadata:created_at 2025_06_25, updated_at 2026_03_23;) Field Validations
Loading…
Comments (0)
Loading comments...