Sagan high stable other

[WINDOWS-SYSMON] Evilginx2 Phishing Framework Execution

[WINDOWS-SYSMON] Evilginx2 Phishing Framework Execution

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SYSMON] Evilginx2 Phishing Framework Execution"; program:*Sysmon*
| *Security*; event_id:1,4688; pcre:"/Image:.*\\\\evilginx/i"; content:"CommandLine"; content:!"-help"; content:!"-version"; classtype:suspicious-command; reference:url,github.com/kgretzky/evilginx2; sid:5015975; rev:1; metadata:created_at 2025_05_23, mitre_tactic_id TA0001, mitre_technique_id T1566.002;)

Field Validations

Loading…

Comments (0)

Loading comments...