From bddbe68235540650ca13c5f6930691981f65d312 Mon Sep 17 00:00:00 2001 From: "S.kiran kumar" Date: Sun, 11 Oct 2020 23:02:03 +0530 Subject: [PATCH] Create silenttrinity_stager_communicating_to_c2.yml --- ...lenttrinity_stager_communicating_to_c2.yml | 21 +++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 rules/windows/sysmon/silenttrinity_stager_communicating_to_c2.yml diff --git a/rules/windows/sysmon/silenttrinity_stager_communicating_to_c2.yml b/rules/windows/sysmon/silenttrinity_stager_communicating_to_c2.yml new file mode 100644 index 000000000..da6f16c2b --- /dev/null +++ b/rules/windows/sysmon/silenttrinity_stager_communicating_to_c2.yml @@ -0,0 +1,21 @@ +title: Silenttrinity Stager Communication To C2 +description: Detects a possible remote connections to Silenttrinity c2 +references: + - https://www.blackhillsinfosec.com/my-first-joyride-with-silenttrinity/ +tags: + - T1127.001 + - Tactic: Defense Evasion +status: experimental +author: Kiran kumar s +date: 11/10/2020 +logsource: + product: windows + service: sysmon +detection: + selection: + EventID: 3 + ParentImage: '*\msbuild.exe' + condition: selection +falsepositives: + - unknown +level: high