Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 830 Bytes

MATCH-S00577.md

File metadata and controls

31 lines (24 loc) · 830 Bytes

Rules: Turla Group Commands

Description

Observes for command lines associated with Turla group

Additional Details

Detail Value
Type Templated Match
Category Unknown/Other
Apply Risk to Entities device_hostname, user_username
Signal Name Turla Group Commands
Summary Expression Turla group associated command line detected on {{device_hostname}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTechnique:T1059, _mitreAttackTechnique:T1059.003

Vendors and Products

Fields Used

Origin Field
Normalized Schema P
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema user_username