Vendor: NetDocs
July 25, 2023 · View on GitHub
Product: NetDocs
Use-Case: Malware
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 7 | 2 | 5 | 5 | 5 |
| Event Type | Rules | Models |
|---|---|---|
| app-activity | T1078 - Valid Accounts ↳ Auth-Blacklist-Shost: User authentication or login from a known blacklisted IP | |
| file-write | T1027 - Obfuscated Files or Information ↳ FW-UMWorkerProcess-FileName-F: First time file creation for Exchange Unified Messaging service UMWorkerProcess.exe T1204 - User Execution ↳ EPA-TEMP-DIRECTORY-F: First execution of this process from a temporary directory on this asset ↳ EPA-TEMP-DIRECTORY-A: Abnormal execution of this process from a temporary directory T1003.002 - T1003.002 ↳ A-ATP-Tool-FGDump: Malicious exe/dll. ↳ A-ATP-Tool-PSTGDump: Malicious pstgdump.exe was run from a temp folder on this asset. T1085 - Signed Binary Proxy Execution: Rundll32 ↳ A-Suspicious-LNK: A suspicious .lnk file used, possible ATP activity on this asset | • A-FW-ProcessName-FileName: File creations for process • A-EPA-UP-TEMP: Processes executed from TEMP directories on this asset |