From e5dfe45bf733f8fe0dcee3478489e32c2245af57 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 18 Jan 2022 19:40:11 -0700 Subject: [PATCH] Update cmd_carry_out_string_command_parameter.yml --- detections/endpoint/cmd_carry_out_string_command_parameter.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml index 0550aed76a..f9bb7e0783 100644 --- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -27,6 +27,7 @@ known_false_positives: False positives may be high based on legitimate scripted in any environment. Filter as needed. references: - https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - IcedID