Rule Library
Sigma Rules
9 rules found for "Mikhail Larin"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Suspicious History File Operations - Linux
Detects commandline operations on shell history files
Linuxauditd
Mikhail Larin+1Sat Oct 17linux
Detectionhightest
Auditing Configuration Changes on Linux Host
Detect changes in auditd configuration files
Linuxauditd
Mikhail Larin+1Fri Oct 25linux
Detectionhightest
Logging Configuration Changes on Linux Host
Detect changes of syslog daemons configuration files
Linuxauditd
Mikhail Larin+1Fri Oct 25linux
Detectionhightest
Binary Padding - MacOS
Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.
macOSProcess Creation
Igor Fits+2Mon Oct 19macos
Detectionmediumtest
File Time Attribute Change
Detect file time attribute change to hide new or changes to existing files
macOSProcess Creation
Igor Fits+2Mon Oct 19macos
Detectionhightest
Credentials In Files
Detecting attempts to extract passwords with grep and laZagne
macOSProcess Creation
Igor Fits+2Mon Oct 19macos
Detectionlowtest
Split A File Into Pieces
Detection use of the command "split" to split files into parts and possible transfer.
macOSProcess Creation
Igor Fits+2Thu Oct 15macos
Detectionmediumtest
Suspicious History File Operations
Detects commandline operations on shell history files
macOSProcess Creation
Mikhail Larin+1Sat Oct 17macos
Detectioninformationaltest
System Shutdown/Reboot - MacOs
Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
macOSProcess Creation
Igor Fits+2Mon Oct 19macos