Files
blue-team-tools/rules/windows/builtin/system/win_system_moriya_rootkit.yml
T
2022-11-30 11:44:15 +01:00

26 lines
687 B
YAML

title: Moriya Rootkit - System
id: 25b9c01c-350d-4b95-bed1-836d04a4f324
status: experimental
description: Detects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report
references:
- https://securelist.com/operation-tunnelsnake-and-moriya-rootkit/101831
author: Bhabesh Raj
date: 2021/05/06
modified: 2022/11/29
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1543.003
logsource:
product: windows
service: system
detection:
selection:
Provider_Name: 'Service Control Manager'
EventID: 7045
ServiceName: ZzNetSvc
condition: selection
falsepositives:
- Unknown
level: critical