Sagan critical stable other
[WINDOWS-SECURITY] Sticky Key Backdoor Registry Addition
[WINDOWS-SECURITY] Sticky Key Backdoor Registry Addition
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Sticky Key Backdoor Registry Addition"; program:*Security*; event_id:4688,1; content:"reg add"; nocase; meta_content:"\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%sagan%.exe",sethc,Magnify,HelpPane,utilman; meta_nocase; content:"cmd.exe"; reference:url,https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/; reference:url,https://www.bleepingcomputer.com/news/security/windows-defender-can-detect-accessibility-tool-backdoors/; classtype:trojan-activity; sid:5015077; rev:1; metadata:deployment Endpoint, created_at 2024_08_13, updated_at 2024_08_13, mitre_tactic_id TA0004, mitre_technique_id T1546.008;) Field Validations
Loading…
Comments (0)
Loading comments...