HackTool - RedMimicry Winnti Playbook Execution
Description
Detects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility
Query · sigma
selection: Image|endswith: - \rundll32.exe - \cmd.exe CommandLine|contains: - gthread-3.6.dll - \Windows\Temp\tmp.bat - sigcmm-2.4.dll condition: selection
Known false positives
- Unknown