Skip to content

Commit a4bfca1

Browse files
authored
Update RootA_Specification.md
1 parent e1c5444 commit a4bfca1

File tree

1 file changed

+7
-7
lines changed

1 file changed

+7
-7
lines changed

RootA_Specification.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -50,10 +50,9 @@ date: 2020-05-24
5050
mitre-attack:
5151
- t1003.001
5252
- t1136.003
53-
timeline: # for Actors and campaigns only
54-
2022-04-01 - 2022-08-08: Bumblebee
55-
2022-07-27: KNOTWEED
56-
2022-12-04: UAC-0082, CERT-UA#4435
53+
detection:
54+
language: splunk-spl-query # elastic-lucene-query, logscale-lql-query, mde-kql-query
55+
body: index=* ((((process="*comsvcs*") AND (process="*MiniDump*")) OR ((process="*comsvcs*") AND (process="*#24*"))) OR ((process="*comsvcs*") AND (process="*full*")))
5756
logsource:
5857
product: Windows # Sigma or OCSF products
5958
log_name: Security # OCSF log names
@@ -63,9 +62,10 @@ logsource:
6362
audit:
6463
source: Windows Security Event Log
6564
enable: Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Detailed Tracking -> Audit Process
66-
detection:
67-
language: splunk-spl-query # elastic-lucene-query, logscale-lql-query, mde-kql-query
68-
body: index=* ((((process="*comsvcs*") AND (process="*MiniDump*")) OR ((process="*comsvcs*") AND (process="*#24*"))) OR ((process="*comsvcs*") AND (process="*full*")))
65+
timeline: # for Actors and campaigns only
66+
2022-04-01 - 2022-08-08: Bumblebee
67+
2022-07-27: KNOTWEED
68+
2022-12-04: UAC-0082, CERT-UA#4435
6969
references:
7070
- https://badoption.eu/blog/2023/06/21/dumpit.html
7171
tags: Bumblebee, UAC-0082, CERT-UA#4435, KNOTWEED, Comsvcs, cir_ttps, ContentlistEndpoint

0 commit comments

Comments
 (0)