Skip to content

Commit ebf600c

Browse files
authored
Update README.md
1 parent a4bfca1 commit ebf600c

File tree

1 file changed

+7
-10
lines changed

1 file changed

+7
-10
lines changed

README.md

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -79,10 +79,9 @@ date: 2020-05-24
7979
mitre-attack:
8080
- t1003.001
8181
- t1136.003
82-
timeline:
83-
2022-04-01 - 2022-08-08: Bumblebee
84-
2022-07-27: KNOTWEED
85-
2022-12-04: UAC-0082, CERT-UA#4435
82+
detection:
83+
language: splunk-spl-query # elastic-lucene-query, logscale-lql-query, mde-kql-query
84+
body: index=* ((((process="*comsvcs*") AND (process="*MiniDump*")) OR ((process="*comsvcs*") AND (process="*#24*"))) OR ((process="*comsvcs*") AND (process="*full*")))
8685
logsource:
8786
product: Windows # Sigma or OCSF products
8887
log_name: Security # OCSF log names
@@ -92,9 +91,10 @@ logsource:
9291
audit:
9392
source: Windows Security Event Log
9493
enable: Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Detailed Tracking -> Audit Process
95-
detection:
96-
language: splunk-spl-query # elastic-lucene-query, logscale-lql-query, mde-kql-query
97-
body: index=* ((((process="*comsvcs*") AND (process="*MiniDump*")) OR ((process="*comsvcs*") AND (process="*#24*"))) OR ((process="*comsvcs*") AND (process="*full*")))
94+
timeline:
95+
2022-04-01 - 2022-08-08: Bumblebee
96+
2022-07-27: KNOTWEED
97+
2022-12-04: UAC-0082, CERT-UA#4435
9898
references:
9999
- https://badoption.eu/blog/2023/06/21/dumpit.html
100100
tags: Bumblebee, UAC-0082, CERT-UA#4435, KNOTWEED, Comsvcs, cir_ttps, ContentlistEndpoint
@@ -125,9 +125,6 @@ To submit your pull request with your ideas or suggestions for changes, take the
125125

126126
Thank you for your contribution to the RootA project!
127127

128-
## Questions & Feedback
129-
Please submit your technical feedback and suggestions to support@socprime.com or a **RootA** channel in [SOC Prime’s Discord](https://discord.gg/socprime). Also, refer to the [guidance for contributors](#how-to-contribute) to support the RootA project or simply [report issues](https://github.com/UncoderIO/RootA/issues).
130-
131128
## Maintainers
132129
Driving the idea of establishing a unified language and toolkit for threat detection and response since 2015, SOC Prime team has developed RootA from the ground up, with major contributions to the project made by:
133130
- Roman Ranskyi

0 commit comments

Comments
 (0)