Hacktool_Strings_p0wnedShell
Description
Detects strings found in Runspace Post Exploitation Toolkit
Query · yara
strings:
$x1 = "Invoke-TokenManipulation" fullword ascii
$x2 = "windows/meterpreter" fullword ascii
$x3 = "lsadump::dcsync" fullword ascii
$x4 = "p0wnedShellx86" fullword ascii
$x5 = "p0wnedShellx64" fullword ascii
$x6 = "Invoke_PsExec()" fullword ascii
$x7 = "Invoke-Mimikatz" fullword ascii
$x8 = "Invoke_Shellcode()" fullword ascii
$x9 = "Invoke-ReflectivePEInjection" ascii
$fp1 = "Sentinel Labs, Inc." wide
$fp2 = "Copyright Elasticsearch B.V." ascii wide
$fp3 = "Attack Information: Invoke-Mimikatz" ascii /* Check Point help files */
$fp4 = "a30226 || INDICATOR-SHELLCODE Metasploit windows/meterpreter stage transfer attempt" /* snort message ID */
$fp5 = "use strict"
condition:
filesize < 20MB
and 1 of ($x*)
and not 1 of ($fp*)