Sagan critical stable other
[WINDOWS-MISC] Command line options used by ExploitRemotingService
[WINDOWS-MISC] Command line options used by ExploitRemotingService
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-MISC] Command line options used by ExploitRemotingService"; program:*Security*
| *Sysmon*; event_id:1,4688; meta_content:"%sagan%",-usecom,-useser,-uselease,-autodir; reference:cve,2022-26503; reference:url,github.com/tyranid/ExploitRemotingService; classtype:trojan-activity; sid:5010738; rev:1;) Field Validations
Loading…
Comments (0)
Loading comments...