Skip to content

Commit 8335168

Browse files
authored
Merge pull request #14 from phantinuss/master
feat: more CobaltStrike malleable C2 profiles
2 parents ea785bc + 569e839 commit 8335168

1 file changed

Lines changed: 17 additions & 0 deletions

File tree

sysmonconfig-export.xml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -935,6 +935,23 @@
935935
<PipeName condition="begin with">\windows.update.manager</PipeName>
936936
<PipeName condition="begin with">\ntsvcs_</PipeName>
937937
<PipeName condition="begin with">\scerpc_</PipeName>
938+
<!-- Malleable C2 profiles https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752 -->
939+
<PipeName condition="begin with">\demoagent_</PipeName>
940+
<PipeName condition="begin with">\PGMessagePipe</PipeName>
941+
<PipeName condition="begin with">\MsFteWds</PipeName>
942+
<PipeName condition="begin with">\f4c3</PipeName>
943+
<PipeName condition="begin with">\fullduplex_</PipeName>
944+
<PipeName condition="begin with">\msrpc_</PipeName>
945+
<PipeName condition="begin with">\win\msrpc_</PipeName>
946+
<PipeName condition="begin with">\f53f</PipeName>
947+
<PipeName condition="begin with">\rpc_</PipeName>
948+
<PipeName condition="begin with">\spoolss_</PipeName>
949+
<PipeName condition="begin with">\win_svc</PipeName>
950+
<PipeName condition="begin with">\SearchTextHarvester</PipeName>
951+
<Rule groupRelation="and"> <!-- would be noisy otherwise as \Winsock2\CatalogchangeListener-???-0 is a legitimate pipe name -->
952+
<PipeName condition="begin with">\Winsock2\CatalogChangeListener-</PipeName>
953+
<PipeName condition="end with">-0,</PipeName>
954+
</Rule>
938955
<!-- these are standard pipes that appear frequently but the Sigma rules use RE to match exactly -->
939956
<PipeName condition="begin with">\scerpc</PipeName>
940957
<PipeName condition="begin with">\ntsvcs</PipeName>

0 commit comments

Comments
 (0)