Skip to content

Latest commit

 

History

History
39 lines (32 loc) · 1.55 KB

MATCH-S00419.md

File metadata and controls

39 lines (32 loc) · 1.55 KB

Rules: Multiple File Extensions

Description

Observes for common file extensions appearing before the actual file extension (ex. totallynotmalware.pdf.exe)

Additional Details

Detail Value
Type Templated Match
Category Defense Evasion
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Multiple File Extensions
Summary Expression File: {{baseImage}} found with multiple extensions on host: {{device_hostname}}
Score/Severity Static: 2
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1036, _mitreAttackTechnique:T1036.007

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema user_username