Detection rules › Sigma
Turla Group Commands May 2020
Detects commands used by Turla group as reported by ESET in May 2020
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Execution | |
| Persistence | |
| Privilege Escalation | |
| Stealth |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Sysmon | Event ID 1: Process creation |
| Security-Auditing | Event ID 4688: A new process has been created. |
Rule body
title: Turla Group Commands May 2020
id: 9e2e51c5-c699-4794-ba5a-29f5da40ac0c
status: test
description: Detects commands used by Turla group as reported by ESET in May 2020
references:
- https://www.welivesecurity.com/wp-content/uploads/2020/05/ESET_Turla_ComRAT.pdf
author: Florian Roth (Nextron Systems)
date: 2020-05-26
modified: 2025-10-19
tags:
- attack.privilege-escalation
- attack.persistence
- attack.stealth
- attack.g0010
- attack.execution
- attack.t1059.001
- attack.t1053.005
- attack.t1027
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_cli_1:
CommandLine|contains:
- 'tracert -h 10 yahoo.com'
- '.WSqmCons))|iex;'
- 'Fr`omBa`se6`4Str`ing'
selection_cli_2:
CommandLine|re: 'net\s+use\s+https://docs.live.net'
CommandLine|contains: '@aol.co.uk'
condition: 1 of selection_*
falsepositives:
- Unknown
level: critical
Stages and Predicates
Stage 0: condition
1 of selection_*Stage 1: selection_cli_1
selection_cli_1:
CommandLine|contains:
- 'tracert -h 10 yahoo.com'
- '.WSqmCons))|iex;'
- 'Fr`omBa`se6`4Str`ing'
Stage 2: selection_cli_2
selection_cli_2:
CommandLine|re: 'net\s+use\s+https://docs.live.net'
CommandLine|contains: '@aol.co.uk'
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
CommandLine | match |
| field:"CommandLine" kind:match |
CommandLine | regex_match |
| field:"CommandLine" kind:regex_match value:"net\s+use\s+https://docs.live.net" |