add additional filename pattern to HiveNightmare rule

This commit is contained in:
Florian Roth 2021-07-23 10:39:41 +02:00
parent 5955efa750
commit c0138d5ced

View File

@ -7,6 +7,7 @@ date: 2020/07/23
references:
- https://github.com/GossiTheDog/HiveNightmare
- https://github.com/FireFart/hivenightmare/
- https://github.com/WiredPulse/Invoke-HiveNightmare
logsource:
product: windows
category: file_event
@ -20,6 +21,7 @@ detection:
- '\hive_sam_' # Go version
- '\SAM-2021-' # C++ version
- '\SAM-2022-' # C++ version
- '\SAM-haxx' # Early C++ versions
- '\Sam.save' # PowerShell version
condition: selection
fields: