Files
blue-team-tools/rules/windows/process_creation/win_susp_renamed_debugview.yml
T
2021-11-27 11:33:14 +01:00

28 lines
663 B
YAML

title: Renamed SysInternals Debug View
id: cd764533-2e07-40d6-a718-cfeec7f2da7f
status: test
description: Detects suspicious renamed SysInternals DebugView execution
author: Florian Roth
references:
- https://www.epicturla.com/blog/sysinturla
date: 2020/05/28
modified: 2021/11/27
logsource:
category: process_creation
product: windows
detection:
selection:
Product:
- 'Sysinternals DebugView'
- 'Sysinternals Debugview'
filter:
OriginalFileName: 'Dbgview.exe'
Image|endswith: '\Dbgview.exe'
condition: selection and not filter
falsepositives:
- Unknown
level: high
tags:
- attack.resource_development
- attack.t1588.002