
Rule Info
Name
Outbound Network Connection To Public IP Via Winlogon
Author
Christopher Peacock @securepeacock, SCYTHE @scythe_io
Description
Detects a "winlogon.exe" process that initiate network communications with public IP addresses
Date
2023-04-28 00:00:00
Modified
2024-03-12 00:00:00
Id
7610a4ea-c06d-495f-a2ac-0a696abcfd3b
Tags
attack.defense-evasion attack.execution attack.command-and-control attack.t1218.011
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
frack113
Merge PR #4765 from @frack113 - Update additional rules to use the `cidr` modifier
2024-03-13
Nasreddine Bencherchali
Merge PR #4761 from @nasbench - Update rules to use CIDR modifier
2024-03-11
github-actions[bot]
Merge PR #4745 from @nasbench - Promote older rules status from `experimental` to `test`
2024-03-01