134. TrueSightKiller: Another Tool to Kill Your EDR

Hello everyone!

I know you enjoy AV\EDR killers, so I decided to share information on another one with you! For example, this tool was used by Earth Ammit. I'm talking about TrueSightKiller.

Just like many other EDR killers, this one creates typical artifacts we can use for detection. For example, it loads truesight.sys driver. We can use it to build our query:

event_type: "driverloadwin"

AND

file_name: "truesight.sys"

Another typical artifact - creating a new service:

event_type: "serviceinstallwin"

AND

service_name: "TrueSight"

And finally, executables' metadata, for example:

event_type: "processcreatewin"

AND

proc_file_productname: "Truesight"

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

001. The Zeltser Challenge