Tim Burrell (MSTIC)
5051334e85
Sigma queries for
...
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-02 14:47:55 +00:00
..
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-01-02 14:47:55 +00:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-19 15:59:07 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-12-30 18:49:39 +09:00