Lace Tempest PowerShell Evidence Eraser

Rule Info

Name
Lace Tempest PowerShell Evidence Eraser
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects a PowerShell script used by Lace Tempest APT to erase evidence from victim servers by exploiting CVE-2023-47246 as reported by SysAid Team
Date
2023-11-09 00:00:00
Modified
None
Id
b377ddab-502d-4519-9e8c-5590033d2d70
Tags
attack.execution attack.t1059.001 detection.emerging-threats
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
Merge PR #5027 from @nasbench - Promote older rules status from `experimental` to `test`
2024-10-01
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
Merge PR #4555 from @nasbench - New ET Rules Related To Lace Tempest / SysAid CVE-2023-47246 Exploitation
2023-11-10