Small Sieve Malware Registry Persistence
Description
Detects registry value with specific intentional typo and strings seen used by the Small Sieve malware
Query · sigma
selection_path: TargetObject|contains: \Microsoft\Windows\CurrentVersion\Run\ selection_value: - TargetObject|contains: Microsift - Details|contains: .exe Platypus condition: all of selection_*
Known false positives
- Unlikely