Skip to content

New mft detection rules#226

Open
Baniur wants to merge 2 commits intoWithSecureLabs:masterfrom
Baniur:master
Open

New mft detection rules#226
Baniur wants to merge 2 commits intoWithSecureLabs:masterfrom
Baniur:master

Conversation

@Baniur
Copy link
Contributor

@Baniur Baniur commented Mar 3, 2026

New rules including detection for RRM tools artefacts:

  1. Atera Agent
  2. MeshAgent
  3. Splashtop

Other detections rules for:

  1. svchost.exe masquerading
  2. svchost.exe in a different location than standard. Potential Malicious Activity.
  3. TokenDuplicator artifacts - https://github.com/magnusstubman/tokenduplicator/
  4. PsExec artifacts (ps64.exe added to original detection rule)

Baniur added 2 commits March 3, 2026 22:49
New mft rules including detection for RRM tools
@Baniur Baniur requested a review from alexkornitzer as a code owner March 3, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant