243003c21a
update: Antivirus Hacktool Detection - Add additional hacktools signature names. update: Antivirus Password Dumper Detection - Add additional password dumpers such as "DumpPert", "Lazagne", "pypykatz", etc. update: Antivirus Ransomware Detection - Add additional ransomware signature names. fix: Antivirus Relevant File Paths Alerts - Remove the path "\Client" as it is too generic for a detection rule. fix: Antivirus Web Shell Detection - Removed overlapping strings "ASP/Agent", "PHP/Agent", "JSP/Agent". --------- Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
71 lines
2.0 KiB
YAML
71 lines
2.0 KiB
YAML
title: Antivirus Hacktool Detection
|
|
id: fa0c05b6-8ad3-468d-8231-c1cbccb64fba
|
|
status: stable
|
|
description: |
|
|
Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool.
|
|
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
|
|
references:
|
|
- https://www.nextron-systems.com/2021/08/16/antivirus-event-analysis-cheat-sheet-v1-8-2/
|
|
- https://www.nextron-systems.com/?s=antivirus
|
|
author: Florian Roth (Nextron Systems), Arnim Rupp
|
|
date: 2021-08-16
|
|
modified: 2024-11-02
|
|
tags:
|
|
- attack.execution
|
|
- attack.t1204
|
|
logsource:
|
|
category: antivirus
|
|
detection:
|
|
selection:
|
|
- Signature|startswith:
|
|
- 'ATK/' # Sophos
|
|
- 'Exploit.Script.CVE'
|
|
- 'HKTL'
|
|
- 'HTOOL'
|
|
- 'PWS.'
|
|
- 'PWSX'
|
|
- 'SecurityTool'
|
|
# - 'FRP.'
|
|
- Signature|contains:
|
|
- 'Adfind'
|
|
- 'Brutel'
|
|
- 'BruteR'
|
|
- 'Cobalt'
|
|
- 'COBEACON'
|
|
- 'Cometer'
|
|
- 'DumpCreds'
|
|
- 'FastReverseProxy'
|
|
- 'Hacktool'
|
|
- 'Havoc'
|
|
- 'Impacket'
|
|
- 'Keylogger'
|
|
- 'Koadic'
|
|
- 'Mimikatz'
|
|
- 'Nighthawk'
|
|
- 'PentestPowerShell'
|
|
- 'Potato'
|
|
- 'PowerSploit'
|
|
- 'PowerSSH'
|
|
- 'PshlSpy'
|
|
- 'PSWTool'
|
|
- 'PWCrack'
|
|
- 'PWDump'
|
|
- 'Rozena'
|
|
- 'Rusthound'
|
|
- 'Sbelt'
|
|
- 'Seatbelt'
|
|
- 'SecurityTool'
|
|
- 'SharpDump'
|
|
- 'SharpHound'
|
|
- 'Shellcode'
|
|
- 'Sliver'
|
|
- 'Snaffler'
|
|
- 'SOAPHound'
|
|
- 'Splinter'
|
|
- 'Swrort'
|
|
- 'TurtleLoader'
|
|
condition: selection
|
|
falsepositives:
|
|
- Unlikely
|
|
level: high
|