Detection rules › Kusto Query Language

Dev-0270 Registry IOC - September 2022

Source
upstream

'The query below identifies modification of registry by Dev-0270 actor to disable security feature as well as to add ransom notes'

MITRE ATT&CK coverage

TacticTechniques
ImpactT1486 Data Encrypted for Impact

Event coverage

ProviderEvent IDTitle
Security-Auditing4688A new process has been created.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: extend

Stage 4: extend

Stage 5: extend