{"id":"fa0c05b6-8ad3-468d-8231-c1cbccb64fba","title":"Antivirus Hacktool Detection","description":"Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"high","date":"2021-08-16","modified":"2024-11-02","tags":["attack.execution","attack.t1204"],"technique_ids":["T1204"],"logsource":{"category":"antivirus"},"falsepositives":["Unlikely"],"references":["https://www.nextron-systems.com/2021/08/16/antivirus-event-analysis-cheat-sheet-v1-8-2/","https://www.nextron-systems.com/?s=antivirus"],"source_path":"rules/category/antivirus/av_hacktool.yml","source_sha256":"b8bb4e6bf427ca9b617ce20d208f9cb5760361d3e2952ef9bd015724619ff967","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/category/antivirus/av_hacktool.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Antivirus Hacktool Detection\nid: fa0c05b6-8ad3-468d-8231-c1cbccb64fba\nstatus: stable\ndescription: |\n    Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool.\n    This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\nreferences:\n    - https://www.nextron-systems.com/2021/08/16/antivirus-event-analysis-cheat-sheet-v1-8-2/\n    - https://www.nextron-systems.com/?s=antivirus\nauthor: Florian Roth (Nextron Systems), Arnim Rupp\ndate: 2021-08-16\nmodified: 2024-11-02\ntags:\n    - attack.execution\n    - attack.t1204\nlogsource:\n    category: antivirus\ndetection:\n    selection:\n        - Signature|startswith:\n              - 'ATK/'  # Sophos\n              - 'Exploit.Script.CVE'\n              - 'HKTL'\n              - 'HTOOL'\n              - 'PWS.'\n              - 'PWSX'\n              - 'SecurityTool'\n              # - 'FRP.'\n        - Signature|contains:\n              - 'Adfind'\n              - 'Brutel'\n              - 'BruteR'\n              - 'Cobalt'\n              - 'COBEACON'\n              - 'Cometer'\n              - 'DumpCreds'\n              - 'FastReverseProxy'\n              - 'Hacktool'\n              - 'Havoc'\n              - 'Impacket'\n              - 'Keylogger'\n              - 'Koadic'\n              - 'Mimikatz'\n              - 'Nighthawk'\n              - 'PentestPowerShell'\n              - 'Potato'\n              - 'PowerSploit'\n              - 'PowerSSH'\n              - 'PshlSpy'\n              - 'PSWTool'\n              - 'PWCrack'\n              - 'PWDump'\n              - 'Rozena'\n              - 'Rusthound'\n              - 'Sbelt'\n              - 'Seatbelt'\n              - 'SecurityTool'\n              - 'SharpDump'\n              - 'SharpHound'\n              - 'Shellcode'\n              - 'Sliver'\n              - 'Snaffler'\n              - 'SOAPHound'\n              - 'Splinter'\n              - 'Swrort'\n              - 'TurtleLoader'\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1204","id":"T1204","name":"User Execution","page":"techniques/enterprise/T1204/"}],"data_path":"data/detection-rules/fa0c05b6-8ad3-468d-8231-c1cbccb64fba.json","kind":"sigma"}
