Rule Library
Sigma Rules
2 rules found for "Tom Ueltschi"
3,731Total
3,132Detection
457Emerging
139Hunting
Emerging Threathightest
Adwind RAT / JRAT
Detects javaw.exe in AppData folder as used by Adwind / JRAT
WindowsProcess Creation
Florian Roth (Nextron Systems)+3Fri Nov 102017
Emerging Threatcriticaltest
NotPetya Ransomware Activity
Detects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil
WindowsProcess Creation
Florian Roth (Nextron Systems)+1Wed Jan 162017