This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Executable from Webdav
Original Source:
[Sigma source]
Title:
Executable from Webdav
Status:
test
Description:
Detects executable access via webdav6. Can be seen in APT 29 such as from the emulated APT 29 hackathon https://github.com/OTRF/detection-hackathon-apt29/
References:
-http://carnal0wnage.attackresearch.com/2012/06/webdav-server-to-download-custom.html
-https://github.com/OTRF/detection-hackathon-apt29
Author:
SOC Prime, Adam Swan
Date:
2020-05-01
modified:
2021-11-27
Tags:
-'attack.command-and-control'
-'attack.t1105'
Logsource:
product: zeek
service: http
Detection:
selection_webdav:
c-useragent|contains
:
'WebDAV'
c-uri|contains
:
'webdav'
selection_executable:
resp_mime_types|contains
:
'dosexec'
c-uri|endswith
:
'.exe'
condition
:
selection_webdav and selection_executable
Falsepositives:
-Unknown
Level:
medium