mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -5,7 +5,7 @@ date: '2020-12-14'
|
||||
description: 'The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost.exe. After a
|
||||
period of 12-14 days, the malware will attempt to resolve a subdomain of avsvmcloud.com. This detections
|
||||
will correlate both events.'
|
||||
how_to_implement: This detection relies on sysmon logs with the Event ID 6, Driver loaded. Please tune your sysmon
|
||||
how_to_implement: This detection relies on sysmon logs with the Event ID 7, Driver loaded. Please tune your sysmon
|
||||
config that you DriverLoad event for SolarWinds.Orion.Core.BusinessLayer.dll is captured by Sysmon. Additionally,
|
||||
you need sysmon logs for Event ID 22, DNS Query. We suggest to run this detection at least once a day over the last 14 days.
|
||||
type: ESCU
|
||||
|
||||
Reference in New Issue
Block a user