mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Delete win_cmd_rar.yml
redundant with ./rules/windows/process_creation/win_data_compressed_with_rar.yml authorship was updated
This commit is contained in:
parent
afb17d0e0e
commit
521d9311c7
@ -1,21 +0,0 @@
|
||||
title: Command-Line Creation of a RAR file
|
||||
description: Detect compression of data into a RAR file using the rar.exe utility.
|
||||
status: experimental
|
||||
author: E.M. Anhaus (orignally from Atomic Blue Detections, Endgame)
|
||||
date: 2019/10/24
|
||||
tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1002
|
||||
detection:
|
||||
selection:
|
||||
Image:
|
||||
- '*rar.exe'
|
||||
CommandLine:
|
||||
- '* a *'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- legit creation of a rar file using cmd
|
||||
level: high
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
Loading…
Reference in New Issue
Block a user