This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - PowerTool Execution
Original Source:
[Sigma source]
Title:
HackTool - PowerTool Execution
Status:
test
Description:
Detects the execution of the tool PowerTool which has the ability to kill a process, delete its process file, unload drivers, and delete the driver files
References:
-https://thedfirreport.com/2022/11/28/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware/
-https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html
-https://twitter.com/gbti_sa/status/1249653895900602375?lang=en
-https://www.softpedia.com/get/Antivirus/Removal-Tools/ithurricane-PowerTool.shtml
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-11-29
modified:
2023-02-04
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
product: windows
category: process_creation
Detection:
selection:
- Image|endswith
:
- '\PowerTool.exe'
- '\PowerTool64.exe'
OriginalFileName
:
'PowerTool.exe'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high