This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Potential CobaltStrike Process Injection
Original Source:
[Sigma source]
Title:
HackTool - Potential CobaltStrike Process Injection
Status:
test
Description:
Detects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons
References:
-https://medium.com/@olafhartong/cobalt-strike-remote-threads-detection-206372d11d0f
-https://blog.cobaltstrike.com/2018/04/09/cobalt-strike-3-11-the-snake-that-eats-its-tail/
Author:
Olaf Hartong, Florian Roth (Nextron Systems), Aleksey Potapov, oscd.community
Date:
2018-11-30
modified:
2023-05-05
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1055.001'
Logsource:
product: windows
category: create_remote_thread
Detection:
selection:
StartAddress|endswith
:
-'0B80'
-'0C7C'
-'0C88'
condition
:
selection
Falsepositives:
-Unknown
Level:
high