Closed swachchhanda000 closed 2 months ago
This PR adds Kapeka backdoor related sigma rules
new: Kapeka Backdoor Autorun Persistence new: Kapeka Backdoor Configuration Persistence new: Kapeka Backdoor Execution Via RunDLL32.EXE new: Kapeka Backdoor Loaded Via Rundll32.EXE new: Kapeka Backdoor Persistence Activity new: Kapeka Backdoor Scheduled Task Creation new: Potential Kapeka Decrypted Backdoor Indicator
Relevant Links:
N/A
Summary of the Pull Request
This PR adds Kapeka backdoor related sigma rules
Changelog
new: Kapeka Backdoor Autorun Persistence new: Kapeka Backdoor Configuration Persistence new: Kapeka Backdoor Execution Via RunDLL32.EXE new: Kapeka Backdoor Loaded Via Rundll32.EXE new: Kapeka Backdoor Persistence Activity new: Kapeka Backdoor Scheduled Task Creation new: Potential Kapeka Decrypted Backdoor Indicator
Example Log Event
Relevant Links:
Fixed Issues
N/A
SigmaHQ Rule Creation Conventions