Detection rules › Equivalence class

eq_0004 — 2 rules with the same canonical form

Vendors: sigma (2). Stage count: 2. Correlation shape: single_event.

Members

Stages and predicates (per member)

Each member's stage rendered in its own native syntax (verbatim source where the IR captures it; falls back to the synthesised native form for the few stage types whose source segments aren't recoverable).

Potential Recon Activity Using DriverQuery.EXE — stage 1 all of selection_img

or:
Image|endswith: driverquery.exe
OriginalFileName: drvqry.exe

Potential Recon Activity Using DriverQuery.EXE — stage 2 all of selection_parent

or:
ParentImage|endswith: '\cscript.exe'
ParentImage|endswith: '\mshta.exe'
ParentImage|endswith: '\regsvr32.exe'
ParentImage|endswith: '\rundll32.exe'
ParentImage|endswith: '\wscript.exe'
ParentImage|contains: '\AppData\Local\'
ParentImage|contains: '\Users\Public\'
ParentImage|contains: '\Windows\Temp\'

DriverQuery.EXE Execution — stage 3 selection

or:
Image|endswith: driverquery.exe
OriginalFileName: drvqry.exe

DriverQuery.EXE Execution — stage 4 not 1 of filter_main_other

or:
ParentImage|endswith: '\cscript.exe'
ParentImage|endswith: '\mshta.exe'
ParentImage|endswith: '\regsvr32.exe'
ParentImage|endswith: '\rundll32.exe'
ParentImage|endswith: '\wscript.exe'
ParentImage|contains: '\AppData\Local\'
ParentImage|contains: '\Users\Public\'
ParentImage|contains: '\Windows\Temp\'

Indicators (across all members)

FieldKindValueMembersCorpus
Imageends_withdriverquery.exe22
OriginalFileNameeqdrvqry.exe22
ParentImageends_with\cscript.exe214
ParentImageends_with\mshta.exe210
ParentImageends_with\regsvr32.exe211
ParentImageends_with\rundll32.exe212
ParentImageends_with\wscript.exe214
ParentImagematch\AppData\Local\23
ParentImagematch\Users\Public\22
ParentImagematch\Windows\Temp\22