fireeye_red_team_tool__adpasshunt_via_cmdline
Description
This rule has been ported from Fireeye's HXIOC format to SIGMA. It detects the Fireeye tool AdPassHunt License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
(re.regex($selection_image.target.process.file.full_path, `.*\\adpasshunt\.exe`) or (re.regex($selection_image.target.process.command_line, `.*dc.*`) and re.regex($selection_image.target.process.command_line, `.*domain.*`) and re.regex($selection_image.target.process.command_line, `.*action.*`) and ($selection_image.metadata.product_event_type = "4688" or $selection_image.metadata.product_event_type = "1") and (re.regex($selection_image.target.process.command_line, `.*gpp.*`) or re.regex($selection_image.target.process.command_line, `.*ad.*`))))
condition:
$selection_image