Leviathan Registry Key Activity
Description
Detects registry key used by Leviathan APT in Malaysian focused campaign
Query · sigma
selection: TargetObject|contains: \Software\Microsoft\Windows\CurrentVersion\Run\ntkd condition: selection
Detects registry key used by Leviathan APT in Malaysian focused campaign
selection: TargetObject|contains: \Software\Microsoft\Windows\CurrentVersion\Run\ntkd condition: selection
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.