Sagan unknown stable other
[WINDOWS-SECURITY] Batch File Inserted Into The Registry
[WINDOWS-SECURITY] Batch File Inserted Into The Registry
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Batch File Inserted Into The Registry"; program:*Security*
| *Sysmon*; event_id:1,4688; content:"reg.exe "; meta_content:"
| 3a
| reg add
| 22
| %sagan%",HKLM,HKCU; meta_nocase; pcre:"/\.bat\x22.{1,10}CurrentDirectory/"; reference:url,https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/; classtype:evasion; sid:5015936; rev:1; metadata:created_at 2025_03_06, updated_at 2025_03_06, mitre_tactic_id TA0005, mitre_technique_id T1112;) Field Validations
Loading…
Comments (0)
Loading comments...