APT_HAFNIUM_Forensic_Artefacts_Mar21_1
Description
Detects forensic artefacts found in HAFNIUM intrusions
Query · yara
strings:
$s1 = "lsass.exe C:\\windows\\temp\\lsass" ascii wide fullword
$s2 = "c:\\ProgramData\\it.zip" ascii wide fullword
$s3 = "powercat.ps1'); powercat -c" ascii wide fullword
condition:
1 of them