Sagan critical stable other

[WINDOWS-SYSMON] PowerShell BitsTransfer Detected

[WINDOWS-SYSMON] PowerShell BitsTransfer Detected

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SYSMON] PowerShell BitsTransfer Detected"; program:*Sysmon*
| *Security*; event_id:1,4688; content:"powershell.exe"; nocase; content:"Import-Module BitsTransfer"; nocase; distance:0; reference:url,thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts/; classtype:trojan-activity; sid:5013797; rev:1; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_02_01, updated_at 2023_02_01, mitre_tactic_id TA0002, mitre_technique_id T1059.001;)

Field Validations

Loading…

Comments (0)

Loading comments...