Rule Library
Sigma Rules
5 rules found for "GossiTheDog"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectioncriticaltest
Certificate Request Export to Exchange Webserver
Detects a write of an Exchange CSR to an untypical directory or with aspx name suffix which can be used to place a webshell
Windowsmsexchange-management
Max Altgelt (Nextron Systems)Mon Aug 23windows
Detectionhightest
HackTool - Typical HiveNightmare SAM File Export
Detects files written by the different tools that exploit HiveNightmare
WindowsFile Event
Florian Roth (Nextron Systems)Fri Jul 23windows
Detectionmediumtest
Suspicious Cabinet File Execution Via Msdt.EXE
Detects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190
WindowsProcess Creation
Nasreddine Bencherchali (Nextron Systems)+2Tue Jun 21windows
Emerging Threatcriticaltest
Exchange Exploitation CVE-2021-28480
Detects successful exploitation of Exchange vulnerability as reported in CVE-2021-28480
Web Server Log
Florian Roth (Nextron Systems)Fri May 142021
Emerging Threatcriticaltest
Potential SystemNightmare Exploitation Attempt
Detects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM
WindowsProcess Creation
Florian Roth (Nextron Systems)Wed Aug 112021