mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
add additional filename pattern to HiveNightmare rule
This commit is contained in:
parent
5955efa750
commit
c0138d5ced
@ -7,6 +7,7 @@ date: 2020/07/23
|
||||
references:
|
||||
- https://github.com/GossiTheDog/HiveNightmare
|
||||
- https://github.com/FireFart/hivenightmare/
|
||||
- https://github.com/WiredPulse/Invoke-HiveNightmare
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
@ -20,6 +21,7 @@ detection:
|
||||
- '\hive_sam_' # Go version
|
||||
- '\SAM-2021-' # C++ version
|
||||
- '\SAM-2022-' # C++ version
|
||||
- '\SAM-haxx' # Early C++ versions
|
||||
- '\Sam.save' # PowerShell version
|
||||
condition: selection
|
||||
fields:
|
||||
|
Loading…
Reference in New Issue
Block a user