Sagan critical stable other

[WINDOWS-POWERSHELL] Hoaxshell Uniq Identifier (PowerShell)

[WINDOWS-POWERSHELL] Hoaxshell Uniq Identifier (PowerShell)

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Hoaxshell Uniq Identifier (PowerShell)"; json_map:"message",".Message"; json_map:"event_id",".EventID"; program:*Sysmon*; event_id:4104,800; content:"Authorization"; meta_content:"$i=
| 27
| %sagan%",bf5e666f-5498a73c-34007c82,add29918-6263f3e6-2f810c1e,e030d4f6-9393dc2a-dd9e00a7,1cdbb583-f96894ff-f99b8edc,11e6bc4b-fefb1eab-68a9612e,add29918-6263f3e6-2f810c1e,e030d4f6-9393dc2a-dd9e00a7; meta_nocase; reference:url,www.revshells.com/; classtype:trojan-activity; sid:5013555; rev:1; metadata:deployment Both,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_07_06, updated_at 2023_10_10, mitre_tactic_id TA0002, mitre_technique_id T1059.001;)

Field Validations

Loading…

Comments (0)

Loading comments...