Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 874 Bytes

MATCH-S00576.md

File metadata and controls

32 lines (25 loc) · 874 Bytes

Rules: Equation Group DLL_U Load

Description

Observes for a tool and export tied to the Equation Group

Additional Details

Detail Value
Type Templated Match
Category Unknown/Other
Apply Risk to Entities device_hostname, user_username
Signal Name Equation Group DLL_U Load
Summary Expression Detected Equation Group tool/export on {{device_hostname}}
Score/Severity Static: 5
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1218, _mitreAttackTechnique:T1218.011

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema commandLine
Normalized Schema commandline
Normalized Schema device_hostname
Normalized Schema user_username