Sponsor of the Day:
Jerkmate
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_webshell_chopper/
Chopper Webshell Process Pattern | Detection.FYI
Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
pattern detection fyichopperwebshellprocess
https://detection.fyi/sigmahq/sigma/web/webserver_generic/web_jndi_exploit/
JNDIExploit Pattern | Detection.FYI
Detects exploitation attempt using the JNDI-Exploit-Kit
pattern detection fyi
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_susp_filefix_execution_pattern/
Suspicious FileFix Execution Pattern | Detection.FYI
Detects suspicious FileFix execution patterns where users are tricked into running malicious commands through browser file upload dialog manipulation. This …
pattern detection fyisuspiciousfilefixexecution
https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-36884/proxy_exploit_cve_2023_36884_office_windows_html_rce/
Potential CVE-2023-36884 Exploitation Pattern | Detection.FYI
Detects a unique pattern seen being used by RomCom potentially exploiting CVE-2023-36884
pattern detection fyipotential cve2023exploitation
https://detection.fyi/sigmahq/sigma/emerging-threats/2023/malware/griffon/proc_creation_win_malware_griffon_patterns/
Griffon Malware Attack Pattern | Detection.FYI
Detects process execution patterns related to Griffon malware as reported by Kaspersky
pattern detection fyimalware attackgriffon
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_hktl_sliver_c2_execution_pattern/
HackTool - Sliver C2 Implant Activity Pattern | Detection.FYI
Detects process activity patterns as seen being used by Sliver C2 framework implants
pattern detection fyihacktoolsliverc2implant
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_uac_bypass_trustedpath/
TrustedPath UAC Bypass Pattern | Detection.FYI
Detects indicators of a UAC bypass method by mocking directories
pattern detection fyiuac bypass