Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

added IOC field in if actions are detected that fit ATT&CK mitre technique #64

Open
wants to merge 7 commits into
base: master
Choose a base branch
from

Conversation

ssi0202
Copy link

@ssi0202 ssi0202 commented Jun 1, 2018

initial compromise via browser (drive by)

spearphising (office suite launches cmd powershell etc.)

tested with embeded code in office documents to launch browser and cmd/powershell

you will need to do a bit of tuning in your sysmon config to get rid of noise from onedrive / groove.exe

@neu5ron
Copy link
Collaborator

neu5ron commented Feb 22, 2019

@ssi0202 can you make sigma rules for these perhaps? this might be a great use case

@ssi0202
Copy link
Author

ssi0202 commented Mar 2, 2019

im lookin into the sigma stuff

this presentation from SANS is really good by the way
https://www.youtube.com/watch?v=PdCQChYrxXg

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants