<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sigma Rule Library — recent critical rules</title><description>The most recently added or modified critical-severity Sigma detection rules from the SigmaHQ repository.</description><link>https://cerez23.github.io/</link><language>en</language><item><title>DC Machine Account Network Logon from Non-DC Source IP</title><link>https://cerez23.github.io/sigma-rule-library/rules/b2e4a719-3c8f-4d1b-a507-f83c2d56e901/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/b2e4a719-3c8f-4d1b-a507-f83c2d56e901/</guid><description>Detects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT - Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host - Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host - Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync (severity: critical)</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>WordPress Wp2shell Webshell Plugin Access</title><link>https://cerez23.github.io/sigma-rule-library/rules/c9e6f412-3d50-4f7e-bf94-5b6c7d8e9f0a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c9e6f412-3d50-4f7e-bf94-5b6c7d8e9f0a/</guid><description>Detects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence. (severity: critical)</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CobaltStrike Named Pipe Pattern Regex</title><link>https://cerez23.github.io/sigma-rule-library/rules/0e7163d4-9e19-4fa7-9be6-000c61aad77a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/0e7163d4-9e19-4fa7-9be6-000c61aad77a/</guid><description>Detects the creation of a named pipe matching a pattern used by CobaltStrike Malleable C2 profiles (severity: critical)</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - APT Malware Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/101a1877-2cf4-474d-abfd-7f6ac4788d1a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/101a1877-2cf4-474d-abfd-7f6ac4788d1a/</guid><description>Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place. (severity: critical)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - Exploitation Framework Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/238527ad-3c2c-4e4f-a1f6-92fd63adb864/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/238527ad-3c2c-4e4f-a1f6-92fd63adb864/</guid><description>Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place. (severity: critical)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - Password Dumper Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/78cc2dd2-7d20-4d32-93ff-057084c38b93/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/78cc2dd2-7d20-4d32-93ff-057084c38b93/</guid><description>Detects a highly relevant Antivirus alert that reports password dumpers and stealers. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset. (severity: critical)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - Ransomware Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/4c6ca276-d4d0-4a8c-9e4c-d69832f8671f/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/4c6ca276-d4d0-4a8c-9e4c-d69832f8671f/</guid><description>Detects a highly relevant Antivirus alert that reports ransomware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place. (severity: critical)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - Remote Access Tools Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/97233998-3838-4581-88c6-f1d19d3993fb/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/97233998-3838-4581-88c6-f1d19d3993fb/</guid><description>Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place. (severity: critical)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>RedSun - Named Pipe Created</title><link>https://cerez23.github.io/sigma-rule-library/rules/9b4e7c2a-3f6d-4a8b-b5e9-1c7d3f2e6a4b/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/9b4e7c2a-3f6d-4a8b-b5e9-1c7d3f2e6a4b/</guid><description>Detects the creation of a named pipe with the hardcoded name &quot;REDSUN&quot;. The RedSun exploit tool uses a pipe with this name for synchronisation and command communication between its components during the Cloud Files API + oplock-based AV bypass and privilege escalation chain. RedSun creates the pipe as \\??\pipe\REDSUN. The pipe server listens for the token-duplicated elevated process to connect and respond, completing the privilege escalation from user to SYSTEM. Presence of this pipe name indicates active or recent RedSun execution. (severity: critical)</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>RedSun - TieringEngineService.exe Detected as EICAR Test File</title><link>https://cerez23.github.io/sigma-rule-library/rules/a7c3e5f2-8b1d-4e9a-b6c2-3d7f5e8a9b4c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/a7c3e5f2-8b1d-4e9a-b6c2-3d7f5e8a9b4c/</guid><description>Detects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe dropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present. This covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based AV bypass/privilege escalation tool. RedSun works as follows: 1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\RS-{GUID}\ 2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger a Defender scan and remediation attempt 3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file 4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open 5. During the oplock break window, RedSun swaps the mount point (junction) to redirect \\?\C:\Windows\System32 to the attacker-controlled temp path 6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges (severity: critical)</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir</title><link>https://cerez23.github.io/sigma-rule-library/rules/f2e4b7d9-5c3a-4f8b-9e1d-7a6c2b3f4e5d/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/f2e4b7d9-5c3a-4f8b-9e1d-7a6c2b3f4e5d/</guid><description>Detects the creation of a file named TieringEngineService.exe inside a directory whose path contains the RS- prefix characteristic of RedSun&apos;s staging directory (e.g. %TEMP%\RS-{GUID}\TieringEngineService.exe). RedSun registers a Cloud Files sync root under this RS-prefixed path and drops a masqueraded placeholder there as part of its oplock-based AV bypass and privilege escalation chain. The RS-{GUID} directory name is generated by RedSun itself and has no legitimate system usage, making the combination of this path prefix and the TieringEngineService.exe filename a highly specific indicator of RedSun activity. (severity: critical)</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Webshell Remote Command Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/c0d3734d-330f-4a03-aae2-65dacc6a8222/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c0d3734d-330f-4a03-aae2-65dacc6a8222/</guid><description>Detects possible command execution by web application/web shell (severity: critical)</description><pubDate>Fri, 05 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Potential Dtrack RAT Activity</title><link>https://cerez23.github.io/sigma-rule-library/rules/f1531fa4-5b84-4342-8f68-9cf3fdbd83d4/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/f1531fa4-5b84-4342-8f68-9cf3fdbd83d4/</guid><description>Detects potential Dtrack RAT activity via specific process patterns (severity: critical)</description><pubDate>Mon, 03 Nov 2025 00:00:00 GMT</pubDate></item><item><title>HackTool - Windows Credential Editor (WCE) Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/7aa7009a-28b9-4344-8c1f-159489a390df/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/7aa7009a-28b9-4344-8c1f-159489a390df/</guid><description>Detects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory. It is often used by threat actors for credential dumping and lateral movement within compromised networks. (severity: critical)</description><pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Mint Sandstorm - AsperaFaspex Suspicious Process Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/91048c0d-5b81-4b85-a099-c9ee4fb87979/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/91048c0d-5b81-4b85-a099-c9ee4fb87979/</guid><description>Detects suspicious execution from AsperaFaspex as seen used by Mint Sandstorm (severity: critical)</description><pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Mint Sandstorm - ManageEngine Suspicious Process Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/58d8341a-5849-44cd-8ac8-8b020413a31b/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/58d8341a-5849-44cd-8ac8-8b020413a31b/</guid><description>Detects suspicious execution from ManageEngine as seen used by Mint Sandstorm (severity: critical)</description><pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Turla Group Commands May 2020</title><link>https://cerez23.github.io/sigma-rule-library/rules/9e2e51c5-c699-4794-ba5a-29f5da40ac0c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/9e2e51c5-c699-4794-ba5a-29f5da40ac0c/</guid><description>Detects commands used by Turla group as reported by ESET in May 2020 (severity: critical)</description><pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate></item><item><title>WannaCry Ransomware Activity</title><link>https://cerez23.github.io/sigma-rule-library/rules/41d40bff-377a-43e2-8e1b-2e543069e079/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/41d40bff-377a-43e2-8e1b-2e543069e079/</guid><description>Detects WannaCry ransomware activity (severity: critical)</description><pubDate>Sat, 18 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create</title><link>https://cerez23.github.io/sigma-rule-library/rules/ba479447-721f-42a9-9af2-6dcd517bbdb3/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/ba479447-721f-42a9-9af2-6dcd517bbdb3/</guid><description>Detects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution. (severity: critical)</description><pubDate>Thu, 24 Jul 2025 00:00:00 GMT</pubDate></item><item><title>TrustedPath UAC Bypass Pattern</title><link>https://cerez23.github.io/sigma-rule-library/rules/4ac47ed3-44c2-4b1f-9d51-bf46e8914126/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/4ac47ed3-44c2-4b1f-9d51-bf46e8914126/</guid><description>Detects indicators of a UAC bypass method by mocking directories (severity: critical)</description><pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate></item><item><title>WCE wceaux.dll Access</title><link>https://cerez23.github.io/sigma-rule-library/rules/1de68c67-af5c-4097-9c85-fe5578e09e67/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/1de68c67-af5c-4097-9c85-fe5578e09e67/</guid><description>Detects wceaux.dll access while WCE pass-the-hash remote command execution on source host (severity: critical)</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate></item><item><title>HackTool - Dumpert Process Dumper Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/2704ab9e-afe2-4854-a3b1-0c0706d03578/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/2704ab9e-afe2-4854-a3b1-0c0706d03578/</guid><description>Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory (severity: critical)</description><pubDate>Wed, 22 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Exploiting CVE-2019-1388</title><link>https://cerez23.github.io/sigma-rule-library/rules/02e0b2ea-a597-428e-b04a-af6a1a403e5c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/02e0b2ea-a597-428e-b04a-af6a1a403e5c/</guid><description>Detects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM (severity: critical)</description><pubDate>Sun, 01 Dec 2024 00:00:00 GMT</pubDate></item><item><title>Potential CVE-2021-41379 Exploitation Attempt</title><link>https://cerez23.github.io/sigma-rule-library/rules/af8bbce4-f751-46b4-8d91-82a33a736f61/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/af8bbce4-f751-46b4-8d91-82a33a736f61/</guid><description>Detects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a &quot;cmd.exe&quot; process as a child of Microsoft Edge elevation service &quot;elevation_service&quot; with &quot;LOCAL_SYSTEM&quot; rights (severity: critical)</description><pubDate>Sun, 01 Dec 2024 00:00:00 GMT</pubDate></item><item><title>HackTool - SysmonEOP Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/8a7e90c5-fe6e-45dc-889e-057fe4378bd9/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/8a7e90c5-fe6e-45dc-889e-057fe4378bd9/</guid><description>Detects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120 (severity: critical)</description><pubDate>Sat, 23 Nov 2024 00:00:00 GMT</pubDate></item><item><title>Hacktool Execution - Imphash</title><link>https://cerez23.github.io/sigma-rule-library/rules/24e3e58a-646b-4b50-adef-02ef935b9fc8/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/24e3e58a-646b-4b50-adef-02ef935b9fc8/</guid><description>Detects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed (severity: critical)</description><pubDate>Sat, 23 Nov 2024 00:00:00 GMT</pubDate></item><item><title>Malicious DLL Load By Compromised 3CXDesktopApp</title><link>https://cerez23.github.io/sigma-rule-library/rules/d0b65ad3-e945-435e-a7a9-438e62dd48e9/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/d0b65ad3-e945-435e-a7a9-438e62dd48e9/</guid><description>Detects DLL load activity of known compromised DLLs used in by the compromised 3CXDesktopApp (severity: critical)</description><pubDate>Sat, 23 Nov 2024 00:00:00 GMT</pubDate></item><item><title>HackTool - Inveigh Execution Artefacts</title><link>https://cerez23.github.io/sigma-rule-library/rules/bb09dd3e-2b78-4819-8e35-a7c1b874e449/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/bb09dd3e-2b78-4819-8e35-a7c1b874e449/</guid><description>Detects the presence and execution of Inveigh via dropped artefacts (severity: critical)</description><pubDate>Thu, 27 Jun 2024 00:00:00 GMT</pubDate></item><item><title>HackTool - Mimikatz Kirbi File Creation</title><link>https://cerez23.github.io/sigma-rule-library/rules/9e099d99-44c2-42b6-a6d8-54c3545cab29/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/9e099d99-44c2-42b6-a6d8-54c3545cab29/</guid><description>Detects the creation of files created by mimikatz such as &quot;.kirbi&quot;, &quot;mimilsa.log&quot;, etc. (severity: critical)</description><pubDate>Thu, 27 Jun 2024 00:00:00 GMT</pubDate></item><item><title>HackTool - QuarksPwDump Dump File</title><link>https://cerez23.github.io/sigma-rule-library/rules/847def9e-924d-4e90-b7c4-5f581395a2b4/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/847def9e-924d-4e90-b7c4-5f581395a2b4/</guid><description>Detects a dump file written by QuarksPwDump password dumper (severity: critical)</description><pubDate>Thu, 27 Jun 2024 00:00:00 GMT</pubDate></item><item><title>FlowCloud Registry Markers</title><link>https://cerez23.github.io/sigma-rule-library/rules/5118765f-6657-4ddb-a487-d7bd673abbf1/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/5118765f-6657-4ddb-a487-d7bd673abbf1/</guid><description>Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware&apos;s keylogger components. (severity: critical)</description><pubDate>Wed, 20 Mar 2024 00:00:00 GMT</pubDate></item><item><title>Bitbucket Unauthorized Access To A Resource</title><link>https://cerez23.github.io/sigma-rule-library/rules/7215374a-de4f-4b33-8ba5-70804c9251d3/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/7215374a-de4f-4b33-8ba5-70804c9251d3/</guid><description>Detects unauthorized access attempts to a resource. (severity: critical)</description><pubDate>Sun, 25 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Bitbucket Unauthorized Full Data Export Triggered</title><link>https://cerez23.github.io/sigma-rule-library/rules/34d81081-03c9-4a7f-91c9-5e46af625cde/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/34d81081-03c9-4a7f-91c9-5e46af625cde/</guid><description>Detects when full data export is attempted an unauthorized user. (severity: critical)</description><pubDate>Sun, 25 Feb 2024 00:00:00 GMT</pubDate></item><item><title>CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security</title><link>https://cerez23.github.io/sigma-rule-library/rules/4c198a60-7d05-4daf-8bf7-4136fb6f5c62/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/4c198a60-7d05-4daf-8bf7-4136fb6f5c62/</guid><description>This detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory. (severity: critical)</description><pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate></item><item><title>CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation</title><link>https://cerez23.github.io/sigma-rule-library/rules/d27eabad-9068-401a-b0d6-9eac744d6e67/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/d27eabad-9068-401a-b0d6-9eac744d6e67/</guid><description>Detects GET requests to &apos;/SetupWizard.aspx/[anythinghere]&apos; that indicate exploitation of the ScreenConnect vulnerability CVE-2024-1709. (severity: critical)</description><pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate></item><item><title>HackTool - BabyShark Agent Default URL Pattern</title><link>https://cerez23.github.io/sigma-rule-library/rules/304810ed-8853-437f-9e36-c4975c3dfd7e/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/304810ed-8853-437f-9e36-c4975c3dfd7e/</guid><description>Detects Baby Shark C2 Framework default communication patterns (severity: critical)</description><pubDate>Thu, 15 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Diamond Sleet APT Scheduled Task Creation</title><link>https://cerez23.github.io/sigma-rule-library/rules/3b8e5084-4de9-449a-a40d-0e11014f2e2d/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/3b8e5084-4de9-449a-a40d-0e11014f2e2d/</guid><description>Detects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability (severity: critical)</description><pubDate>Tue, 24 Oct 2023 00:00:00 GMT</pubDate></item><item><title>Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection</title><link>https://cerez23.github.io/sigma-rule-library/rules/6fe1719e-ecdf-4caf-bffe-4f501cb0a561/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/6fe1719e-ecdf-4caf-bffe-4f501cb0a561/</guid><description>Detects the suspicious file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare), CVE-2021-1675 . (severity: critical)</description><pubDate>Mon, 23 Oct 2023 00:00:00 GMT</pubDate></item><item><title>OceanLotus Registry Activity</title><link>https://cerez23.github.io/sigma-rule-library/rules/4ac5fc44-a601-4c06-955b-309df8c4e9d4/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/4ac5fc44-a601-4c06-955b-309df8c4e9d4/</guid><description>Detects registry keys created in OceanLotus (also known as APT32) attacks (severity: critical)</description><pubDate>Thu, 28 Sep 2023 00:00:00 GMT</pubDate></item><item><title>Leviathan Registry Key Activity</title><link>https://cerez23.github.io/sigma-rule-library/rules/70d43542-cd2d-483c-8f30-f16b436fd7db/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/70d43542-cd2d-483c-8f30-f16b436fd7db/</guid><description>Detects registry key used by Leviathan APT in Malaysian focused campaign (severity: critical)</description><pubDate>Tue, 19 Sep 2023 00:00:00 GMT</pubDate></item><item><title>CVE-2021-31979 CVE-2021-33771 Exploits</title><link>https://cerez23.github.io/sigma-rule-library/rules/32b5db62-cb5f-4266-9639-0fa48376ac00/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/32b5db62-cb5f-4266-9639-0fa48376ac00/</guid><description>Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum (severity: critical)</description><pubDate>Thu, 17 Aug 2023 00:00:00 GMT</pubDate></item><item><title>HackTool - Credential Dumping Tools Named Pipe Created</title><link>https://cerez23.github.io/sigma-rule-library/rules/961d0ba2-3eea-4303-a930-2cf78bbfcc5e/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/961d0ba2-3eea-4303-a930-2cf78bbfcc5e/</guid><description>Detects well-known credential dumping tools execution via specific named pipe creation (severity: critical)</description><pubDate>Mon, 07 Aug 2023 00:00:00 GMT</pubDate></item><item><title>HackTool - DiagTrackEoP Default Named Pipe</title><link>https://cerez23.github.io/sigma-rule-library/rules/1f7025a6-e747-4130-aac4-961eb47015f1/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/1f7025a6-e747-4130-aac4-961eb47015f1/</guid><description>Detects creation of default named pipe used by the DiagTrackEoP POC, a tool that abuses &quot;SeImpersonate&quot; privilege. (severity: critical)</description><pubDate>Mon, 07 Aug 2023 00:00:00 GMT</pubDate></item><item><title>HackTool - Koh Default Named Pipe</title><link>https://cerez23.github.io/sigma-rule-library/rules/0adc67e0-a68f-4ffd-9c43-28905aad5d6a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/0adc67e0-a68f-4ffd-9c43-28905aad5d6a/</guid><description>Detects creation of default named pipes used by the Koh tool (severity: critical)</description><pubDate>Mon, 07 Aug 2023 00:00:00 GMT</pubDate></item><item><title>Malicious Named Pipe Created</title><link>https://cerez23.github.io/sigma-rule-library/rules/fe3ac066-98bb-432a-b1e7-a5229cb39d4a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/fe3ac066-98bb-432a-b1e7-a5229cb39d4a/</guid><description>Detects the creation of a named pipe seen used by known APTs or malware. (severity: critical)</description><pubDate>Mon, 07 Aug 2023 00:00:00 GMT</pubDate></item><item><title>Potential CVE-2023-36884 Exploitation Pattern</title><link>https://cerez23.github.io/sigma-rule-library/rules/0066d244-c277-4c3e-88ec-9e7b777cc8bc/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/0066d244-c277-4c3e-88ec-9e7b777cc8bc/</guid><description>Detects a unique pattern seen being used by RomCom potentially exploiting CVE-2023-36884 (severity: critical)</description><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate></item><item><title>UNC4841 - Potential SEASPY Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/f6a711f3-d032-4f9e-890b-bbe776236c84/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/f6a711f3-d032-4f9e-890b-bbe776236c84/</guid><description>Detects execution of specific named binaries which were used by UNC4841 to deploy their SEASPY backdoor (severity: critical)</description><pubDate>Fri, 16 Jun 2023 00:00:00 GMT</pubDate></item><item><title>PrinterNightmare Mimikatz Driver Name</title><link>https://cerez23.github.io/sigma-rule-library/rules/ba6b9e43-1d45-4d3c-a504-1043a64c8469/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/ba6b9e43-1d45-4d3c-a504-1043a64c8469/</guid><description>Detects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527 (severity: critical)</description><pubDate>Mon, 12 Jun 2023 00:00:00 GMT</pubDate></item><item><title>Qakbot Rundll32 Exports Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/339ed3d6-5490-46d0-96a7-8abe33078f58/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/339ed3d6-5490-46d0-96a7-8abe33078f58/</guid><description>Detects specific process tree behavior of a &quot;rundll32&quot; execution with exports linked with Qakbot activity. (severity: critical)</description><pubDate>Tue, 30 May 2023 00:00:00 GMT</pubDate></item><item><title>Qakbot Rundll32 Fake DLL Extension Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/bfd34392-c591-4009-b938-9fd985a28b85/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/bfd34392-c591-4009-b938-9fd985a28b85/</guid><description>Detects specific process tree behavior of a &quot;rundll32&quot; execution where the DLL doesn&apos;t have the &quot;.dll&quot; extension. This is often linked with potential Qakbot activity. (severity: critical)</description><pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate></item></channel></rss>