mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -4,7 +4,7 @@ version: 1
|
||||
date: '2023-07-26'
|
||||
author: Teoderick Contreras, Splunk
|
||||
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities
|
||||
that might related to warzone (ve maria) RAT. This analytic story looks for suspicious process execution, command-line activity, downloads, persistence, defense evasion and more.
|
||||
that might related to warzone (Ave maria) RAT. This analytic story looks for suspicious process execution, command-line activity, downloads, persistence, defense evasion and more.
|
||||
narrative: Warzone RAT, also known as Ave Maria, is a sophisticated remote access trojan (RAT) that surfaced in January 2019.
|
||||
Originally offered as malware-as-a-service (MaaS), it rapidly gained notoriety and became one of the most prominent malware strains by 2020.
|
||||
Its exceptional capabilities in stealth and anti-analysis techniques make it a formidable threat in various campaigns, including those targeting sensitive geopolitical entities.
|
||||
|
||||
Reference in New Issue
Block a user