Detection rules › Sigma

PUA - Mouse Lock Execution

Severity
medium
Author
Cian Heasley
Source
upstream

In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.

MITRE ATT&CK coverage

TacticTechniques
Credential AccessT1056.002 Input Capture: GUI Input Capture
CollectionT1056.002 Input Capture: GUI Input Capture

Event coverage

ProviderEvent IDTitle
Sysmon1Process creation

Stages and Predicates

Stage 1: selection

or:
CommandLine|contains: 'Mouse Lock_'
Company|contains: Misc314
Product|contains: 'Mouse Lock'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLinematch
  • Mouse Lock_
Companymatch
  • Misc314
Productmatch
  • Mouse Lock