Skip to content

Detection Rules

Kriyos Arcane edited this page Jul 4, 2026 · 1 revision

Detection Rules

TrustMeBro ships YARA and Sigma rules in the detection/ directory. These detect the tool's own techniques. Operators should test payloads against these before deployment.

Rule Index

Rule Format What it catches What a defender sees Bypassed by
trustmebro_sip_hijack.yar YARA Files containing SIP GUID strings + DbgUiContinue + CryptSIPDllVerifyIndirectData A script, binary, or registry export referencing the hijack setup strings Nothing. Static string match on the tool itself.
trustmebro_sip_hijack_registry.sigma Sigma Registry write to any CryptSIPDllVerifyIndirectData key Sysmon Event ID 13 showing the SIP key path with a new Dll value --wow64-only (only fires if the SIEM monitors the WOW6432Node path)
trustmebro_finalpolicy_hijack.sigma Sigma FinalPolicy registration under a non-standard action GUID with SoftpubCleanup Sysmon Event ID 13 showing $Function = SoftpubCleanup under a GUID other than the Authenticode GUID The rule filters OUT the well-known Authenticode GUID. So the standard --finalpolicy hijack is NOT caught by this rule. Only --custom-provider is.
trustmebro_sigstash_embed.yar YARA Tool source referencing PKCS#7 OIDs, or signed PEs with WIN_CERTIFICATE larger than 32KB A PE file with an unusually large certificate region, or a script containing SigStash-related strings Camouflage mode makes the OID look legitimate, but the size heuristic still fires on large payloads

Usage

# Scan a file
yara detection/trustmebro_sip_hijack.yar target.exe

# Scan a directory
yara -r detection/trustmebro_sigstash_embed.yar C:\Temp\

Sigma rules require a SIEM or log pipeline. Convert with sigma-cli or sigmac for your backend (Splunk, Elastic, etc).

What is NOT Detected

  • FinalPolicy hijack on the well-known Authenticode GUID ({00AAC56B-...}). The Sigma rule intentionally excludes this GUID to reduce false positives from legitimate wintrust operations. The standard --finalpolicy hijack writes to this key.
  • SigStash payloads smaller than 32KB. The YARA size heuristic only fires above 32KB.
  • SIP execution surface implants if the operator uses a custom GUID not in the YARA string set.
  • FormatGhost registration. No detection rule ships for CryptDllFormatObject key writes. Write your own Sigma rule targeting that registry path.

Clone this wiki locally