security_content
security_content copied to clipboard
Nterl0k - [T1574] Hijacks Gone Wild 2
Details
Rewrote the previous tstats based search to work solely on EID7, while using backwards compatible evals/extractions in the detection.
It's less efficient cause no tstats, but shouldn't break with TA changes.
Checklist
- [ ] Validate name matches
<platform>_<mitre att&ck technique>_<short description>nomenclature - [ ] CI/CD jobs passed ✔️
- [ ] Validated SPL logic.
- [ ] Validated tags, description, and how to implement.
- [ ] Verified references match analytic.
@patel-bhavin - I did the thing, enjoy.