Skip to content

Commit

Permalink
Add rule for detecting hiding shutdown actions (#935)
Browse files Browse the repository at this point in the history
* Add initial rule for hiding shutdown actions

Signed-off-by: Still Hsu <[email protected]>

---------

Signed-off-by: Still Hsu <[email protected]>
Co-authored-by: Moritz <[email protected]>
  • Loading branch information
Still34 and mr-tz authored Sep 26, 2024
1 parent 1fd0d8e commit 9da73be
Showing 1 changed file with 31 additions and 0 deletions.
31 changes: 31 additions & 0 deletions host-interaction/os/hide-shutdown-actions-via-policy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
rule:
meta:
name: hide shutdown actions via policy
namespace: host-interaction/os
authors:
- [email protected]
scopes:
static: function
dynamic: call
att&ck:
- Defense Evasion::Modify Registry [T1112]
references:
- https://securelist.com/mallox-ransomware/113529/
examples:
- a6594d9550d56ddeaac8b3140821e698eefb7163ba29f0119c2ef19beb6040b0:0x14000b47f
features:
- and:
- optional:
- match: create or open registry key
- or:
- and:
- string: "/Policies/i"
- or:
- string: "/ShutdownWithoutLogon/i"
- string: "/HidePowerOptions/i"
- and:
- string: "/PolicyManager/i"
- or:
- string: "/HideRestart/i"
- string: "/HideShutDown/i"
- string: "/HideSignOut/i"

0 comments on commit 9da73be

Please sign in to comment.