-
Notifications
You must be signed in to change notification settings - Fork 17
Detection Rules
Kriyos Arcane edited this page Jul 4, 2026
·
1 revision
TrustMeBro ships YARA and Sigma rules in the detection/ directory. These detect the tool's own techniques. Operators should test payloads against these before deployment.
| Rule | Format | What it catches | What a defender sees | Bypassed by |
|---|---|---|---|---|
trustmebro_sip_hijack.yar |
YARA | Files containing SIP GUID strings + DbgUiContinue + CryptSIPDllVerifyIndirectData | A script, binary, or registry export referencing the hijack setup strings | Nothing. Static string match on the tool itself. |
trustmebro_sip_hijack_registry.sigma |
Sigma | Registry write to any CryptSIPDllVerifyIndirectData key | Sysmon Event ID 13 showing the SIP key path with a new Dll value |
--wow64-only (only fires if the SIEM monitors the WOW6432Node path) |
trustmebro_finalpolicy_hijack.sigma |
Sigma | FinalPolicy registration under a non-standard action GUID with SoftpubCleanup | Sysmon Event ID 13 showing $Function = SoftpubCleanup under a GUID other than the Authenticode GUID | The rule filters OUT the well-known Authenticode GUID. So the standard --finalpolicy hijack is NOT caught by this rule. Only --custom-provider is. |
trustmebro_sigstash_embed.yar |
YARA | Tool source referencing PKCS#7 OIDs, or signed PEs with WIN_CERTIFICATE larger than 32KB | A PE file with an unusually large certificate region, or a script containing SigStash-related strings | Camouflage mode makes the OID look legitimate, but the size heuristic still fires on large payloads |
# Scan a file
yara detection/trustmebro_sip_hijack.yar target.exe
# Scan a directory
yara -r detection/trustmebro_sigstash_embed.yar C:\Temp\Sigma rules require a SIEM or log pipeline. Convert with sigma-cli or sigmac for your backend (Splunk, Elastic, etc).
- FinalPolicy hijack on the well-known Authenticode GUID (
{00AAC56B-...}). The Sigma rule intentionally excludes this GUID to reduce false positives from legitimate wintrust operations. The standard--finalpolicyhijack writes to this key. - SigStash payloads smaller than 32KB. The YARA size heuristic only fires above 32KB.
- SIP execution surface implants if the operator uses a custom GUID not in the YARA string set.
- FormatGhost registration. No detection rule ships for CryptDllFormatObject key writes. Write your own Sigma rule targeting that registry path.