Sagan critical stable other

[WINDOWS-SYSMON] Process started from ProgramData with Network Connection Port 389

[WINDOWS-SYSMON] Process started from ProgramData with Network Connection Port 389

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SYSMON] Process started from ProgramData with Network Connection Port 389"; program:*Sysmon*
| *Security*; event_id:3;  meta_content:"Image
| 3a
| %sagan%",c
| 3a 5c
| ProgramData,c
| 3a 5c 5c
| ProgramData; meta_nocase; content:"DestinationPort
| 3a
| 389 "; nocase; content:!"DestinationIp
| 3a
| 127.0.0.1"; meta_content:!"%sagan%",MpCmdRun
| 2e
| exe,VC_redist
| 2e
| x64
| 2e
| exe,bomgar,Netwrix,Citrix,XenDesktop,AzureWindowsBaseline; meta_nocase; reference:url,thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/; classtype:trojan-activity; sid:5013800; rev:2; metadata:deployment Both,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_02_01, updated_at 2026_02_16, mitre_tactic_id TA0002, mitre_technique_id T1059;)

Field Validations

Loading…

Comments (0)

Loading comments...