Writing Yara Rules for Fun and Profit: Notes from the FireEye Breach Countermeasures, (Thu, Dec 10th)

SANS Internet Storm Center, InfoCON: green 2020-12-11

Summary:

By now, everyone should have seen that FireEye got breached and their red team tools got stolen. What is truly unique about their response is publishing detection rules&#;x26;#;xc2;&#;x26;#;xa0;to detect the use of those tools in the wild. However, the nature of some of those rules is that the detection will be short-lived. This isn&#;x26;#;39;t necessarily a fault of FireEye (as I will explain below) but it is useful as an exercise in writing Yara rules (or Snort, HXIOC, STIX, et al).

Link:

https://isc.sans.edu/diary/rss/26870

From feeds:

Intel Hub » T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

12/11/2020, 12:23

Date published:

12/11/2020, 11:03