Sagan unknown stable other

[WINDOWS-SECURITY] Batch File Inserted Into The Registry

[WINDOWS-SECURITY] Batch File Inserted Into The Registry

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Batch File Inserted Into The Registry"; program:*Security*
| *Sysmon*; event_id:1,4688; content:"reg.exe "; meta_content:"
| 3a
| reg add
| 22
| %sagan%",HKLM,HKCU; meta_nocase; pcre:"/\.bat\x22.{1,10}CurrentDirectory/"; reference:url,https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/; classtype:evasion; sid:5015936; rev:1; metadata:created_at 2025_03_06, updated_at 2025_03_06, mitre_tactic_id TA0005, mitre_technique_id T1112;)

Field Validations

Loading…

Comments (0)

Loading comments...