APT_PS1_SysAid_EXPL_ForensicArtifacts_Nov23_1
Description
Detects forensic artifacts found in attacks on SysAid on-prem software exploiting CVE-2023-47246
Query · yara
strings:
$x1 = "if ($s -match '^(Sophos).*\\.exe\\s') {echo $s; $bp++;}" ascii wide
$x2 = "$s=$env:SehCore;$env:SehCore=\"\";Invoke-Expression $s;" ascii wide
condition:
1 of them