Skip to content

Some BlueHammer detections#4037

Open
RavenTait wants to merge 3 commits into
developfrom
bluehammer_redsun
Open

Some BlueHammer detections#4037
RavenTait wants to merge 3 commits into
developfrom
bluehammer_redsun

Conversation

@RavenTait
Copy link
Copy Markdown
Contributor

Contains detections and stories around BlueHammer and RedSun as well as a new data source for Windows 4723

Detections:

  • Windows Admin Password Changed by Non-Admin
  • Windows MsMpEng Writing to System32
  • Windows Non-System Process Querying Definition Update
  • Windows Suspicious Burst of Password Changes
  • Windows Suspicious Defender Engine or Signature Files Created
  • Windows Suspicious Defender Update Activity in INetCache

Stories:

  • BlueHammer
  • RedSun

Comment thread detections/endpoint/windows_admin_password_changed_by_non_admin.yml Outdated
Comment thread detections/endpoint/windows_admin_password_changed_by_non_admin.yml Outdated
Comment thread detections/endpoint/windows_admin_password_changed_by_non_admin.yml Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants