Skip to content

Commit

Permalink
Merge PR SigmaHQ#4773 from @DefenderDaniel - Add rules covering Nscur…
Browse files Browse the repository at this point in the history
…l usage

new: File Download Via Nscurl - MacOS 

---------

Co-authored-by: nasbench <[email protected]>
  • Loading branch information
DefenderDaniel and nasbench authored Jun 5, 2024
1 parent 06eaf2c commit d7bd600
Showing 1 changed file with 32 additions and 0 deletions.
32 changes: 32 additions & 0 deletions rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
title: File Download Via Nscurl - MacOS
id: 6d8a7cf1-8085-423b-b87d-7e880faabbdf
status: experimental
description: Detects the execution of the nscurl utility in order to download files.
references:
- https://www.loobins.io/binaries/nscurl/
- https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl
- https://gist.github.com/nasbench/ca6ef95db04ae04ffd1e0b1ce709cadd
author: Daniel Cortez
date: 2024/06/04
tags:
- attack.defense_evasion
- attack.command_and_control
- attack.t1105
logsource:
category: process_creation
product: macos
detection:
selection:
Image|endswith: '/nscurl'
CommandLine|contains:
- '--download '
- '--download-directory '
- '--output '
- '-dir '
- '-dl '
- '-ld'
- '-o '
condition: selection
falsepositives:
- Legitimate usage of nscurl by administrators and users.
level: medium

0 comments on commit d7bd600

Please sign in to comment.