Create silenttrinity_stager_communicating_to_c2.yml

This commit is contained in:
S.kiran kumar
2020-10-11 23:02:03 +05:30
committed by GitHub
parent 6b0b779480
commit bddbe68235
@@ -0,0 +1,21 @@
title: Silenttrinity Stager Communication To C2
description: Detects a possible remote connections to Silenttrinity c2
references:
- https://www.blackhillsinfosec.com/my-first-joyride-with-silenttrinity/
tags:
- T1127.001
- Tactic: Defense Evasion
status: experimental
author: Kiran kumar s
date: 11/10/2020
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 3
ParentImage: '*\msbuild.exe'
condition: selection
falsepositives:
- unknown
level: high