Skip to content

Commit

Permalink
Merge PR SigmaHQ#4675 from @X-Junior - New Emerging Threat Rules For …
Browse files Browse the repository at this point in the history
…Peach Sandstorm APT

new: Peach Sandstorm APT Process Activity Indicators
new: Potential Peach Sandstorm APT C2 Communication Activity 

---------

Co-authored-by: nasbench <[email protected]>
Co-authored-by: phantinuss <[email protected]>
  • Loading branch information
3 people authored Jan 15, 2024
1 parent feded2f commit 3fb5392
Show file tree
Hide file tree
Showing 3 changed files with 47 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
title: Peach Sandstorm APT Process Activity Indicators
id: 2e7bbd54-2f26-476e-b4a1-ba5f1a012614
status: experimental
description: Detects process creation activity related to Peach Sandstorm APT
references:
- https://twitter.com/MsftSecIntel/status/1737895710169628824
- https://www.virustotal.com/gui/file/364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614/details
author: X__Junior (Nextron Systems)
date: 2024/01/15
tags:
- attack.execution
- detection.emerging_threats
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains: 'QP''s\*(58vaP!tF4'
condition: selection
falsepositives:
- Unlikely
level: high
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
title: Potential Peach Sandstorm APT C2 Communication Activity
id: b8225208-81d0-4715-a822-12bcdd583e0f
status: experimental
description: Detects potential C2 communication activity related to Peach Sandstorm APT
references:
- https://twitter.com/MsftSecIntel/status/1737895710169628824
- https://www.virustotal.com/gui/file/364275326bbfc4a3b89233dabdaf3230a3d149ab774678342a40644ad9f8d614/details
author: X__Junior (Nextron Systems)
date: 2024/01/15
tags:
- attack.command_and_control
- detection.emerging_threats
logsource:
category: proxy
detection:
selection:
cs-method: 'GET'
c-uri|endswith:
- '/api/Core/Command/Init'
- '/api/Core/Command/Restart'
condition: selection
falsepositives:
- Unknown
level: medium
1 change: 1 addition & 0 deletions tests/sigma_cli_conf.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,7 @@ exclusions:
f6de6525-4509-495a-8a82-1f8b0ed73a00: escaped_wildcard
fb502828-2db0-438e-93e6-801c7548686d: escaped_wildcard
59e938ff-0d6d-4dc3-b13f-36cc28734d4e: escaped_wildcard
2e7bbd54-2f26-476e-b4a1-ba5f1a012614: escaped_wildcard
# number_as_string
5c84856b-55a5-45f1-826f-13f37250cf4e: number_as_string
85b88e05-dadc-430b-8a9e-53ff1cd30aae: number_as_string
Expand Down

0 comments on commit 3fb5392

Please sign in to comment.