Theft of Operational Information T0882

ICS Tactic: Impact

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (5 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
AlertName1contains 1connection attempt to known malicious ip, invalid smb message (doublepulsar backdoor implant), malicious domain name request
DeviceProduct1eq 1isid
EventClassID1in 1147, 193, 194
ProviderName1eq 1IoTSecurity
isNew1eq 1True

Top indicator values (16 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
AlertNamecontains
connection attempt to known malicious ip
1
AlertNamecontains
invalid smb message (doublepulsar backdoor implant)
1
AlertNamecontains
malicious domain name request
1
AlertNamecontains
malware
1
AlertNamecontains
suspicion of malicious activity
1
AlertNamecontains
suspicion of remote code execution with psexec
1
AlertNamecontains
suspicion of remote windows service management
1
AlertNamecontains
suspicious executable file detected on endpoint
1
AlertNamecontains
suspicious traffic detected
1
DeviceProducteq
isid
18
EventClassIDin
147
1
EventClassIDin
193
1
EventClassIDin
194
1
EventClassIDin
55
1
ProviderNameeq
IoTSecurity
115
isNeweq
True
115

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Kusto 2 rules