Detection rules › Sigma

Antivirus - Hacktool Signature

Status
stable
Severity
high
Log source
category antivirus
Author
Florian Roth (Nextron Systems), Arnim Rupp
Source
github.com/SigmaHQ/sigma

Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.

Known false positives

  • Unlikely

MITRE ATT&CK coverage

TacticTechniques
Execution

Rule body

title: Antivirus - Hacktool Signature
id: fa0c05b6-8ad3-468d-8231-c1cbccb64fba
status: stable
description: |
    Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool.
    This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
references:
    - https://www.nextron-systems.com/2021/08/16/antivirus-event-analysis-cheat-sheet-v1-8-2/
    - https://www.nextron-systems.com/?s=antivirus
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2021-08-16
modified: 2026-06-15
tags:
    - attack.execution
    - attack.t1204
logsource:
    category: antivirus
detection:
    selection:
        - Signature|startswith:
              - 'ATK/'  # Sophos
              - 'Exploit.Script.CVE'
              - 'HKTL'
              - 'HTOOL'
              - 'PWS.'
              - 'PWSX'
              - 'SecurityTool'
              # - 'FRP.'
        - Signature|contains:
              - 'Adfind'
              - 'BloodH'
              - 'BloodyAD'
              - 'Brutel'
              - 'BruteR'
              - 'Cobalt'
              - 'COBEACON'
              - 'Cometer'
              - 'DumpCreds'
              - 'EDRfreeze'
              - 'FastReverseProxy'
              - 'Hacktool'
              - 'Havoc'
              - 'Impacket'
              - 'Keylogger'
              - 'Koadic'
              - 'Mimikatz'
              - 'Nighthawk'
              - 'PentestPowerShell'
              - 'Potato'
              - 'PowerSploit'
              - 'PowerSSH'
              - 'PshlSpy'
              - 'PSWTool'
              - 'PWCrack'
              - 'PWDump'
              - 'Responder'
              - 'Rozena'
              - 'Rusthound'
              - 'Sbelt'
              - 'Seatbelt'
              - 'SecurityTool'
              - 'SharpDump'
              - 'SharpHound'
              - 'Shellcode'
              - 'Sliver'
              - 'Snaffler'
              - 'SOAPHound'
              - 'Splinter'
              - 'Stowaway'
              - 'Swrort'
              - 'Trojan.Hound'
              - 'TurtleLoader'
              - 'Undefend'
              - 'Undfnd'
    condition: selection
falsepositives:
    - Unlikely
level: high

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    - Signature|startswith:
          - 'ATK/'
          - 'Exploit.Script.CVE'
          - 'HKTL'
          - 'HTOOL'
          - 'PWS.'
          - 'PWSX'
          - 'SecurityTool'
    - Signature|contains:
          - 'Adfind'
          - 'BloodH'
          - 'BloodyAD'
          - 'Brutel'
          - 'BruteR'
          - 'Cobalt'
          - 'COBEACON'
          - 'Cometer'
          - 'DumpCreds'
          - 'EDRfreeze'
          - 'FastReverseProxy'
          - 'Hacktool'
          - 'Havoc'
          - 'Impacket'
          - 'Keylogger'
          - 'Koadic'
          - 'Mimikatz'
          - 'Nighthawk'
          - 'PentestPowerShell'
          - 'Potato'
          - 'PowerSploit'
          - 'PowerSSH'
          - 'PshlSpy'
          - 'PSWTool'
          - 'PWCrack'
          - 'PWDump'
          - 'Responder'
          - 'Rozena'
          - 'Rusthound'
          - 'Sbelt'
          - 'Seatbelt'
          - 'SecurityTool'
          - 'SharpDump'
          - 'SharpHound'
          - 'Shellcode'
          - 'Sliver'
          - 'Snaffler'
          - 'SOAPHound'
          - 'Splinter'
          - 'Stowaway'
          - 'Swrort'
          - 'Trojan.Hound'
          - 'TurtleLoader'
          - 'Undefend'
          - 'Undfnd'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
Signaturematch
  • Adfind
  • BloodH
  • BloodyAD
  • BruteR
  • Brutel
  • COBEACON
  • Cobalt
  • Cometer
  • DumpCreds
  • EDRfreeze
  • FastReverseProxy
  • Hacktool
  • Havoc
  • Impacket
  • Keylogger
  • Koadic
  • Mimikatz
  • Nighthawk
  • PSWTool
  • PWCrack
  • PWDump
  • PentestPowerShell
  • Potato
  • PowerSSH
  • PowerSploit
  • PshlSpy
  • Responder
  • Rozena
  • Rusthound
  • SOAPHound
  • Sbelt
  • Seatbelt
  • SecurityTool
  • SharpDump
  • SharpHound
  • Shellcode
  • Sliver
  • Snaffler
  • Splinter
  • Stowaway
  • Swrort
  • Trojan.Hound
  • TurtleLoader
  • Undefend
  • Undfnd
field:"Signature" kind:match
Signaturestarts_with
  • ATK/
  • Exploit.Script.CVE
  • HKTL
  • HTOOL
  • PWS.
  • PWSX
  • SecurityTool
field:"Signature" kind:starts_with