HKTL_RedSun_Privilege_Escalation_Apr26
Description
Detects RedSun hacktool used for privilege escalation through Microsoft Defender.
Query · yara
strings:
$x1 = "\\??\\pipe\\REDSUN" wide
$x2 = "The red sun shall prevail.\n" ascii fullword
$x3 = "\\RedSun.pdb" ascii
$s1 = "\\System32\\TieringEngineService.exe" wide
$s2 = "SERIOUSLYMSFT" wide
$s3 = "*H+H$!ELIF-TSET-SURIVITNA-DRADNATS-RACIE$}7)CC7)^P(45XZP\\4[PA@%P!O5X" ascii
condition:
uint16(0) == 0x5a4d
and (
1 of ($x*)
or 2 of ($s*)
)
or 3 of them