May 13, 2024, 9:15 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

SigmaHQ Rules Release Highlights — r2024–05–13

https://github.com/SigmaHQ/sigma/releases/tag/r2024-05-13

Sigma Rule Packages for 13–05–2024 are released and available for download. This release saw the addition of 16 new rules, 7 rule updates and 1 rule fix by 7 contributors.

New Rules

Some highlights for the newer rules include, rules covering different cases on how Wbadmin can be abused to dump/restore sensitive files and delete backups.

title: File Recovery From Backup Via Wbadmin.EXE
id: 6fe4aa1e-0531-4510-8be2-782154b73b48
related:
- id: 84972c80-251c-4c3a-9079-4f00aad93938
type: derived …

article link may release rules topic

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)