Rule Library
Sigma Rules
5 rules found for "Daniil Yugoslavskiy"
3,731Total
3,132Detection
457Emerging
139Hunting
Emerging Threatcriticaltest
CosmicDuke Service Installation
Detects the installation of a service named "javamtsup" on the system. The CosmicDuke info stealer uses Windows services typically named "javamtsup" for persistence.
Windowssecurity
Florian Roth (Nextron Systems)+2Mon Mar 272017
Emerging Threatcriticaltest
OilRig APT Activity
Detects OilRig activity as reported by Nyotron in their March 2018 report
WindowsProcess Creation
Florian Roth (Nextron Systems)+4Fri Mar 232018
Emerging Threatcriticaltest
OilRig APT Registry Persistence
Detects OilRig registry persistence as reported by Nyotron in their March 2018 report
WindowsRegistry Event
Florian Roth (Nextron Systems)+4Fri Mar 232018
Emerging Threatcriticaltest
OilRig APT Schedule Task Persistence - Security
Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
Windowssecurity
Florian Roth (Nextron Systems)+4Fri Mar 232018
Emerging Threatcriticaltest
OilRig APT Schedule Task Persistence - System
Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
Windowssystem
Florian Roth (Nextron Systems)+4Fri Mar 232018