refactor: slightly improved Greenbug rule

This commit is contained in:
Florian Roth 2020-05-21 13:38:11 +02:00
parent 9a3b6c1c77
commit 91c4c4ecc5

View File

@ -6,6 +6,7 @@ references:
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/greenbug-espionage-telco-south-asia
author: Florian Roth
date: 2020/05/20
modified: 2020/05/21
tags:
- attack.g0049
logsource:
@ -17,9 +18,7 @@ detection:
- 'bitsadmin /transfer'
- 'CSIDL_APPDATA'
selection2:
CommandLine|contains|all:
- 'PowerShell.exe'
- '-ExecutionPolicy Bypass'
CommandLine|contains:
- 'CSIDL_SYSTEM_DRIVE'
selection3:
CommandLine|contains: