Sagan critical stable other

[WINDOWS-SYSMON] MSHTA executing powershell

[WINDOWS-SYSMON] MSHTA executing powershell

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SYSMON] MSHTA executing powershell"; program:*Sysmon*
| *Security*; event_id:1,4688; content:"CommandLine"; nocase; content:"powershell.exe"; distance:0; nocase; content:"ParentCommandLine"; nocase; distance:0; content:"mshta.exe"; nocase; distance:0; reference:url,thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts/; classtype:trojan-activity; sid:5013833; rev:1; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_02_01, updated_at 2023_02_01, mitre_tactic_id TA0005, mitre_technique_id T1218.005;)

Field Validations

Loading…

Comments (0)

Loading comments...