Skip to content

In "NotPetya Ransomware Activity" rule, for which field we have this selection: select_perfc_keyword. #3498

Closed Answered by nasbench
qasimqlf asked this question in Q&A
Discussion options

You must be logged in to vote

To my knowledge, In SIGMA a keyword selection means that look in all the fields described by the logsource section. In this specifc case, you should look for the keyword "perfc.dat" in all the fields of process creation (ie 4688 and Sysmon EID 1).

Just to get the idea across, for example this rule 06d71506-7beb-4f22-8888-e2e5e2ca7fd8 will look in all the windows event logs available for those specific keywords. (Because no category was specified)

I hope this helps :D

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by qasimqlf
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants