SigmaHQ/wazuh/rules/sigma_win_apt_lazarus_session_highjack.yml

16 lines
461 B
YAML
Raw Normal View History

2020-12-02 22:43:30 +00:00
alert:
- debug
description: Detects executables launched outside their default directories as used by Lazarus Group (Bluenoroff)
filter:
- query:
query_string:
query: (data.win.eventdata.image.keyword:(*\\msdtc.exe OR *\\gpvc.exe) AND (NOT (data.win.eventdata.image.keyword:(C\:\\Windows\\System32\\* OR C\:\\Windows\\SysWOW64\\*))))
index: wazuh-alerts-3.x-*
name: 3f7f5b0b-5b16-476c-a85f-ab477f6dd24b_0
priority: 2
realert:
minutes: 0
type: any