Rule Library
Sigma Rules
2 rules found for "Dray Agha"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhighexperimental
Devcon Execution Disabling VMware VMCI Device
Detects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device. This can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device. This has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.
WindowsProcess Creation
Matt Anderson+2Fri Jan 02windows
Detectionhighexperimental
PUA - Kernel Driver Utility (KDU) Execution
Detects execution of the Kernel Driver Utility (KDU) tool. KDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel. Potentially allowing for privilege escalation, persistence, or evasion of security controls.
WindowsProcess Creation
Matt Anderson+2Fri Jan 02windows