Sagan critical stable other

[WINDOWS-SECURITY] Atera Stop/Delete Service

[WINDOWS-SECURITY] Atera Stop/Delete Service

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Atera Stop/Delete Service"; program:*Security*; event_id:4688,1; meta_content:"sc %sagan% AteraAgent",stop,delete; reference:url,https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/; reference:url,https://community.atera.com/discussion/240/atera-agent-found-malicious-by-bitdefender/p2; classtype:trojan-activity; sid:5015073; rev:1; metadata:deployment Endpoint, created_at 2024_08_13, updated_at 2024_08_13, mitre_tactic_id TA0040, mitre_technique_id T1489;)

Field Validations

Loading…

Comments (0)

Loading comments...