mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Merge pull request #565 from RiccardoAncarani/master
Add Covenant default named pipe
This commit is contained in:
commit
376092cfd3
@ -30,6 +30,7 @@ detection:
|
||||
- '\NamePipe_MoreWindows' # Cloud Hopper Annex B https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf, US-CERT Alert - RedLeaves https://www.us-cert.gov/ncas/alerts/TA17-117A
|
||||
- '\pcheap_reuse' # Pipe used by Equation Group malware 77486bb828dba77099785feda0ca1d4f33ad0d39b672190079c508b3feb21fb0
|
||||
- '\msagent_*' # CS default named pipes https://github.com/Neo23x0/sigma/issues/253
|
||||
- '\gruntsvc' # Covenant default named pipe
|
||||
# - '\status_*' # CS default named pipes https://github.com/Neo23x0/sigma/issues/253
|
||||
condition: selection
|
||||
tags:
|
||||
|
Loading…
Reference in New Issue
Block a user