Sagan high stable other
[WINDOWS-SYSMON] Attack on Sysmon - Process Injection
[WINDOWS-SYSMON] Attack on Sysmon - Process Injection
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SYSMON] Attack on Sysmon - Process Injection"; program:*Sysmon*; json_map:"event_id",".EventID"; json_map:"message",".RenderedDescription"; event_id:10; content:"TargetImage
| 3a
| "; nocase; meta_content:"%sagan%",sysmon.exe,sysmon64.exe; meta_distance:0; meta_nocase; content:"GrantedAccess
| 3a
| 0x1FFFFF"; nocase; reference:url,codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html; reference:url,github.com/matterpreter/Shhmon; classtype:suspicious-command; sid:5009800; metadata: created_on 2022_11_22, old_sid 5007698; rev:1;) Field Validations
Loading…
Comments (0)
Loading comments...