SigmaHQ/wazuh/rules/sigma_sysmon_apt_muddywater_dnstunnel.yml
joker2013 50379800f2 123
2020-12-03 01:43:30 +03:00

16 lines
421 B
YAML

alert:
- debug
description: Detecting DNS tunnel activity for Muddywater actor
filter:
- query:
query_string:
query: (data.win.eventdata.image.keyword:(*\\powershell.exe) AND data.win.eventdata.parentImage.keyword:(*\\excel.exe) AND data.win.eventdata.commandLine.keyword:(*DataExchange.dll*))
index: wazuh-alerts-3.x-*
name: 36222790-0d43-4fe8-86e4-674b27809543_0
priority: 1
realert:
minutes: 0
type: any