microsoft / Microsoft-365-Defender-Hunting-Queries

Sample queries for Advanced hunting in Microsoft 365 Defender
MIT License
1.94k stars 539 forks source link

Create EarthBaku-APT-41-files-domains.txt #414

Open Phoenix9032 opened 3 years ago

Phoenix9032 commented 3 years ago

This is the files and network activities query for resurfaced Barium /APT41/DoubleDragon Group which has come up with new techniques like StealthMutant and StealthVector . The researchlink is in https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/earth-baku-returns?utm_source=trendmicroresearch&utm_medium=smk&utm_campaign=0821_EarthBaku1