Rule Library
Sigma Rules
5 rules found for "Cian Heasley"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Webshell ReGeorg Detection Via Web Logs
Certain strings in the uri_query field when combined with null referer and null user agent can indicate activity associated with the webshell ReGeorg.
Web Server Log
Cian HeasleyTue Aug 04web
Detectionmediumtest
Windows Pcap Drivers
Detects Windows Pcap driver installation based on a list of associated .sys files.
Windowssecurity
Cian HeasleyWed Jun 10windows
Detectioninformationaltest
Windows Defender Malware Detection History Deletion
Windows Defender logs when the history of detected infections is deleted.
Windowswindefend
Cian HeasleyThu Aug 13windows
Detectionmediumtest
PUA - Mouse Lock Execution
In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
WindowsProcess Creation
Cian HeasleyThu Aug 13windows
Detectionhightest
Webshell Tool Reconnaissance Activity
Detects processes spawned from web servers (PHP, Tomcat, IIS, etc.) that perform reconnaissance looking for the existence of popular scripting tools (perl, python, wget) on the system via the help commands
WindowsProcess Creation
Cian Heasley+1Wed Jul 22windows