-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add playbook trigger for remote psexec lolbin command execution playb…
…ook (#32205) * Add playbook trigger * Update release notes * Fix validation error * Fix field name according to review * Update release notes
- Loading branch information
1 parent
63053ae
commit 18b04de
Showing
4 changed files
with
24 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
#### Triggers Recommendations | ||
|
||
- New: **Remote PsExec with LOLBIN command execution alert** |
19 changes: 19 additions & 0 deletions
19
Packs/Core/Triggers/Trigger_-_Remote_PsExec_with_LOLBIN_command_execution_alert.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
{ | ||
"trigger_id": "155e823d9d56d1e3cec9061cd9c0523d", | ||
"playbook_id": "Remote PsExec with LOLBIN command execution alert", | ||
"suggestion_reason": "Recommended for Remote PsExec with LOLBIN command execution alerts", | ||
"description": "This trigger is responsible for handling Remote PsExec with LOLBIN command execution alerts", | ||
"trigger_name": "Remote PsExec with LOLBIN command execution alert", | ||
"fromVersion": "6.10.0", | ||
"alerts_filter": { | ||
"filter": { | ||
"AND": [ | ||
{ | ||
"SEARCH_FIELD": "alert_name", | ||
"SEARCH_TYPE": "EQ", | ||
"SEARCH_VALUE": "Remote PsExec-like LOLBIN command execution from an unsigned non-standard PsExec service" | ||
} | ||
] | ||
} | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters