Dev-0228 File Path Hashes November 2021

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This hunting query looks for file paths/hashes related to observed activity by Dev-0228. The actor is known to use custom version of popular tool like PsExec, Procdump etc. to carry its activity. The risk score associated with each result is based on a number of factors, hosts with higher risk events should be investigated first.

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 3b443f22-9be9-4c35-ac70-a94757748439
Severity High
Kind Scheduled
Tactics CredentialAccess, Execution
Techniques T1569, T1003
Required Connectors MicrosoftDefenderAdvancedThreatProtection, MicrosoftThreatProtection
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules