Robuta

Sponsor of the Day: Jerkmate
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_webshell_chopper/ Chopper Webshell Process Pattern | Detection.FYI Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells pattern detection fyichopperwebshellprocess https://detection.fyi/sigmahq/sigma/web/webserver_generic/web_jndi_exploit/ JNDIExploit Pattern | Detection.FYI Detects exploitation attempt using the JNDI-Exploit-Kit pattern detection fyi https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_susp_filefix_execution_pattern/ Suspicious FileFix Execution Pattern | Detection.FYI Detects suspicious FileFix execution patterns where users are tricked into running malicious commands through browser file upload dialog manipulation. This … pattern detection fyisuspiciousfilefixexecution https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-36884/proxy_exploit_cve_2023_36884_office_windows_html_rce/ Potential CVE-2023-36884 Exploitation Pattern | Detection.FYI Detects a unique pattern seen being used by RomCom potentially exploiting CVE-2023-36884 pattern detection fyipotential cve2023exploitation https://detection.fyi/sigmahq/sigma/emerging-threats/2023/malware/griffon/proc_creation_win_malware_griffon_patterns/ Griffon Malware Attack Pattern | Detection.FYI Detects process execution patterns related to Griffon malware as reported by Kaspersky pattern detection fyimalware attackgriffon https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_hktl_sliver_c2_execution_pattern/ HackTool - Sliver C2 Implant Activity Pattern | Detection.FYI Detects process activity patterns as seen being used by Sliver C2 framework implants pattern detection fyihacktoolsliverc2implant https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_uac_bypass_trustedpath/ TrustedPath UAC Bypass Pattern | Detection.FYI Detects indicators of a UAC bypass method by mocking directories pattern detection fyiuac bypass