Pandemic Registry Key
Detects Pandemic Windows Implant
Detection logic
selection
TargetObject|contains: \SYSTEM\CurrentControlSet\services\null\InstanceCondition
selectionRaw YAML
title: Pandemic Registry Key
id: 47e0852a-cf81-4494-a8e6-31864f8c86ed
status: test
description: Detects Pandemic Windows Implant
references:
- https://wikileaks.org/vault7/#Pandemic
- https://twitter.com/MalwareJake/status/870349480356454401
author: Florian Roth (Nextron Systems)
date: 2017-06-01
modified: 2022-10-09
tags:
- attack.command-and-control
- attack.t1105
- detection.emerging-threats
logsource:
category: registry_event
product: windows
detection:
selection:
TargetObject|contains: '\SYSTEM\CurrentControlSet\services\null\Instance'
condition: selection
falsepositives:
- Unknown
level: criticalFalse positives
- Unknown
References
Similar rules
Axios NPM Compromise Indicators - Windows
highwindows · Shares T1105
DarkGate - Autoit3.EXE File Creation By Uncommon Process
mediumwindows · Shares T1105
Greenbug Espionage Group Indicators
criticalwindows · Shares T1105
Potential Exploitation of RCE Vulnerability CVE-2025-33053
highwindows · Shares T1105