Skip to content

Instantly share code, notes, and snippets.

@0xtf
Last active December 11, 2020 16:11
Show Gist options
  • Save 0xtf/15c0d247e1b5cf3c197bb73423f11001 to your computer and use it in GitHub Desktop.
Save 0xtf/15c0d247e1b5cf3c197bb73423f11001 to your computer and use it in GitHub Desktop.
title: NIDS FireEye Breached Red Team Tool Detected
id: ce129fbc-5c2e-4e49-ac2d-9742afa10c25
status: experimental
description: A red team tool, from the FireEye breach, has been detected.
author: 3CORESec
date: 2020/12/09
modified: 2020/12/10
references:
- https://github.com/fireeye/red_team_tool_countermeasures
tags:
- attack.command_and_control
- attack.t1071.001
- attack.t1071.004
- attack.resource_development
- attack.t1587.003
- attack.credential_access
- attack.t1558
level: high
logsource:
product: nids
detection:
selection:
event_type: alert
alert.signature_id:
- "2031264"
- "2031265"
- "2031266"
- "2031267"
- "2031268"
- "2031269"
- "2031270"
- "2031273"
- "2031274"
- "2031275"
- "2031276"
- "2031277"
- "2031278"
- "2031279"
- "2031280"
- "2031281"
- "2031282"
- "2031283"
- "2031284"
- "2031285"
- "2031286"
- "2031287"
- "2031288"
- "2031289"
- "2031290"
- "2031291"
- "2031292"
- "2031293"
- "2031294"
- "2031295"
- "2031296"
- "2031297"
- "2031299"
- "2031300"
- "2031301"
- "2031302"
- "2031303"
- "2031304"
- "2031305"
- "2031306"
- "2031307"
- "2031308"
condition: selection
falsepositives:
- unknown
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment