File Creation Related To RAT Clients

Rule Info

Name
File Creation Related To RAT Clients
Author
Joseliyo Sanchez, @Joseliyo_Jstnk
Description
File .conf created related to VenomRAT, AsyncRAT and Lummac samples observed in the wild.
Date
2024-12-19 00:00:00
Modified
None
Id
2f3039c8-e8fe-43a9-b5cf-dcd424a2522d
Tags
attack.execution detection.emerging-threats
Type
Community Rule

Rule History

Author
Title
Date
Commit
frack113
Merge PR #5169 from @frack113 - Add missing `detection.emerging-threats` tags
2025-01-30
jstnk9
Merge PR #5123 from @jstnk9 - Add new sigma rules related to lummac and RATs behaviors observed ITW
2024-12-19